EU’s 24-Hour Exploit Deadline Forces Payment Terminal Makers Toward Continuous Testing

CRA compliance drives continuous security testing

Payment terminal makers now face a 24-hour deadline to report actively exploited vulnerabilities under the European Union’s Cyber Resilience Act (CRA). Failure to meet that timeline could expose manufacturers to regulatory action, while banks and payment providers shoulder the operational fallout.

The reporting obligations took effect on 11 September 2026. They demand an initial alert within one day of discovering a severe security incident or actively exploited flaw, followed by a full notification within 72 hours. Full CRA enforcement lands in December 2027, yet these early deadlines already test how quickly manufacturers can triage incidents and understand their own product fleets.

William Bartram, managing director of PCA Cyber Security, told QA Financial that the regulation does not explicitly mandate continuous testing. However, he believes lifecycle security requirements will push the industry in that direction regardless. “Being CRA compliant is going to require a level of ongoing visibility into product security,” he said. “I expect in-scope organisations will come to the realisation, if they haven’t already, that this does entail continuous security testing.”

Visibility remains the biggest weakness for many terminal manufacturers. Determining whether a newly discovered vulnerability affects a specific firmware release or deployed configuration depends on accurate product and deployment data. Bartram warned that many companies lack detailed records linking software versions to individual device lines. Without this information, meeting the 24-hour reporting window becomes guesswork.

Software bills of materials should help, but Bartram described their maturity as uneven. Many SBOMs list first- and second-tier components yet miss deeper dependency chains involving open-source libraries and third-party code. That gap leaves manufacturers unable to confirm whether an affected component sits inside their devices.

Once a vulnerable terminal gets identified, manufacturers must ship an update without breaking transaction reliability. Regression testing plays a central role here. Bartram stressed that its primary function is maintenance and stability, not security control. Still, it must integrate with security testing to verify that a patch fixes the intended flaw without creating new ones.

Banks, PSPs, and merchants also carry risk. Bartram urged these organisations to demand better vulnerability information, accurate SBOMs, and timely patches from terminal suppliers. But he added that such demands must pair with internal discipline: current device inventories and rigorous patch management.

The CRA shifts payment-device security away from point-in-time certification toward continuous assurance. Manufacturers that build mature vulnerability-management programmes, backed by accurate SBOMs and deployment data, stand the best chance of surviving the new reporting reality.