Invesaro
Teza inwestycyjna · Aktywna

AI writes the exploits, Brussels writes the rules, and the certification labs write the invoices

The EU Cyber Resilience Act starts biting on 11 September 2026, turning product cybersecurity into a recurring audit fee collected by the TIC oligopoly.

Opublikowano 28 sierpnia 2026 · horyzont 180 dni · regulacje

Ta analiza nie została jeszcze przetłumaczona na ten język, więc pokazujemy oryginał. Tłumaczenie pojawi się wkrótce.

Łańcuch przyczynowy: AI cuts exploit development from weeks to hours → EU Cyber Resilience Act reporting starts 11 Sep 2026 → Every connected product sold in the EU needs SBOM, vulnerability handling and a cyber CE m → Important and critical classes require third party conformity assessment → Notified body capacity is scarce, so audit slots are rationed and priced up → Certification becomes a recurring per product, per update fee → Testing and certification oligopoly collects the fee

Na czym stoi ta teza

Każdy punkt to zdanie, które musi być prawdziwe. Do każdej żywej tezy wracamy w stałym rytmie i zestawiamy te punkty z publicznymi źródłami, więc przy każdym stoi albo to, co znaleźliśmy, albo data następnej kontroli.

Sprawdzane co 14 dni. Pierwszy przegląd 11 września 2026.

  1. The EU does not postpone the Cyber Resilience Act's vulnerability reporting obligation beyond its 11 September 2026 start date.

    regulacje · Otwarte

    Pierwsza kontrola 11 września 2026

  2. The Commission does not remove smart home devices, VPNs, password managers or network management systems from the Cyber Resilience Act's important product classes before 30 June 2027.

    regulacje · Otwarte

    Pierwsza kontrola 11 września 2026

  3. At least 10 notified bodies are designated for the Cyber Resilience Act in the EU NANDO database before 30 June 2027.

    operacje · Otwarte

    Pierwsza kontrola 11 września 2026

  4. At least two of UL Solutions, Bureau Veritas, SGS and Intertek publicly launch a dedicated Cyber Resilience Act conformity or readiness service before 30 April 2027.

    konkurencja · Otwarte

    Pierwsza kontrola 11 września 2026

  5. UL Solutions reports organic revenue growth of at least 5% year over year in each of the two quarterly results published after this thesis.

    finanse · Otwarte

    Pierwsza kontrola 11 września 2026

Założenia zapisujemy po angielsku, bo w tym języku jest większość źródeł, z którymi je zestawiamy.

The date nobody in the market has circled

A hundred technology companies spent this week warning that AI is about to compress the time between a vulnerability being disclosed and a working exploit existing from weeks to hours. The market reflex is to buy cybersecurity software. That reflex misses the more mechanical consequence, which arrives on a fixed calendar date: on 11 September 2026, two weeks from now, the EU Cyber Resilience Act's reporting obligations switch on. From that day, any manufacturer placing a product with digital elements on the EU market must send an early warning to ENISA and the relevant national CSIRT within 24 hours of learning that a vulnerability in its product is being actively exploited, with a fuller notification inside 72 hours.

Otwórz interaktywną tezę

Interaktywna mapa przyczynowa, wykres koszyka na tle rynku i pełna oś czasu tezy.

Otwórz w Invesaro →

Nowe tezy prosto na maila

Zapisz się, a wyślemy Ci każdą nową tezę i każdy werdykt. Zero spamu, wypisanie jednym kliknięciem.

To analiza, a nie porada inwestycyjna ani rekomendacja kupna lub sprzedaży. Publikujemy ją i śledzimy publicznie, razem z pomyłkami. Decyzję podejmujesz sam i na własne ryzyko.