SSolarc Labs

Evidence first · answer first · no doorway permutations

Buyer-intent answers that lead to a working proof.

Each page targets one distinct operational decision, cites primary sources, states boundaries, and links into a matching free-proof app instead of creating thin keyword variants.

16 evidence-complete answersPrimary-source gatedFree proof path

EU Cyber Resilience Act · reporting · 11 September 2026

CRA Reporting From 11 September 2026: What the 24h and 72h Steps Mean

From 11 September 2026, Article 14 of the Cyber Resilience Act applies to manufacturer reporting obligations for actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements. The European Commission says manufacturers need an early warning within 24 hours of becoming aware and a full notification within 72 hours through the CRA Single Reporting Platform. The Commission also describes later final-report deadlines: no later than 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability, and within one month from the 72-hour submission for a severe incident.

Open answer

Companies House · ACSP · identity evidence

Companies House ACSP Records: Build a 7-Year Identity-Check Evidence File

An Authorised Corporate Service Provider must keep records of the evidence and information used to verify a person for Companies House for seven years from the date the identity verification is completed. Companies House says this includes copies of documents checked, evidence of the checks completed and records of failed verification attempts. When an ACSP tells Companies House it has verified someone, it must also retain the submitted verification details and be able to provide evidence if Companies House asks for it.

Open answer

HMRC · CIS · monthly returns

CIS Nil Returns in 2026: Decide Between a Nil Return and an Inactivity Request

For mainstream CIS contractors, HMRC says the obligation to file a nil return was reinstated from 6 April 2026. If no subcontractor payments were made for the period, the contractor should either file a monthly return showing zero payments or tell HMRC that it has temporarily stopped using subcontractors through an inactivity request. Doing neither can lead to a late-filing penalty, so the no-payment decision should be treated as a monthly close control rather than simply leaving the return blank.

Open answer

OTSI · trade sanctions · mandatory reporting

OTSI Suspected-Breach Reporting: Build the Initial Evidence Pack Before You Submit

Providers of legal or financial services and money service businesses have a legal reporting obligation when, in the course of business, they know or have reasonable cause to suspect that a trade-sanctions breach has occurred. OTSI guidance says the initial report must be made as soon as practicable; further information can be supplied afterwards. The practical control is therefore to preserve the evidence behind the suspicion, identify the relevant parties and transaction or activity, submit the initial report without waiting for a perfect investigation file, and keep a traceable record of later supplements.

Open answer

HMRC · Plastic Packaging Tax · mass balance

Plastic Packaging Tax Mass Balance: Prepare the Certification Evidence for April 2027

From 1 April 2027, a business that wants to account for chemically recycled plastic through the Plastic Packaging Tax mass-balance approach needs a qualifying evidence chain. HMRC says relevant supply-chain businesses must be certified under a scheme that meets the minimum requirements, site-level mass balance must use three-month accounting periods with no negative balance, and businesses must keep valid certificates, attribution declarations and required site-specific records. Records must be retained for six years, and suppliers’ certification and attribution declarations need due-diligence checks before the recycled content is relied on for the return.

Open answer

HMRC · tax advisers · registration

HMRC Tax Adviser Registration: What to Do After a Missed 2026 Window

HMRC updated its guidance on 3 September 2026 after the first registration window ended. If you missed your window, or you are new to the market and need to register, HMRC says you should register now. The registration process uses an agent services account, and advisers normally have three months from the date their registration window opens to apply. Before applying, confirm that the business meets HMRC’s conditions, identify the entity and services in scope, and assemble the information needed for the application.

Open answer

HMRC agents · MFA · access continuity

HMRC Agent MFA: Prepare Before the Final 28 September–15 October Activation

HMRC says all remaining agent accounts that have not already activated multi-factor authentication will be switched on at some point between 28 September and 15 October 2026, without a specific activation date for each account. Before that window, practices should inventory agent IDs and users, confirm administrator ownership, choose workable access-code methods, remove outdated MFA settings, test recovery and document how shared operational work will continue if one user is unavailable.

Open answer

HMRC · Vaping Products Duty · monthly return

Vaping Products Duty: Prepare the First Monthly Return Due 7 November 2026

HMRC requires approved UK vaping manufacturers to submit a return for every calendar month, including a nil return when nothing was manufactured. The first return is due on 7 November 2026. Before filing, reconcile the month’s manufactured liquid volume to batch or production evidence, check the relevant duty points and measurement rules, identify adjustments or exceptions, and retain the supporting workpaper that explains how the return figures were produced.

Open answer

UK CBAM · import threshold · records

UK CBAM £50,000 Threshold: Build the Import and Record-Keeping Control Before 2027

From 1 January 2027, an importer of in-scope CBAM goods must monitor both a forward-looking and backward-looking value test. The forward test asks whether at least £50,000 of CBAM goods is expected over the next 30 days; the backward test is checked on the first day of each month against relevant imports in the preceding 12 months, with the first year looking back only to 1 January 2027. Importers also need written or electronic records for CBAM goods and generally must keep those records for six years.

Open answer

FCA · short selling · reporting migration

FCA Short Selling Phase 2: Prepare for Bulk Position Submissions by 30 November 2026

The FCA’s phase-2 short-selling system change takes effect on 30 November 2026 and will allow multiple positions to be uploaded and submitted in one bulk submission. Firms should inventory their current position-reporting export, identifiers and control totals, preserve a known-good sample corpus, then compare it with the FCA’s updated operational guidance and ESS requirements before cutover. The FCA indicated that supporting operational documentation would be updated ahead of phase 2, so the migration check should be rerun when that documentation changes.

Open answer

Twilio · REST API · TLS rotation

Twilio REST TLS Certificate Rotation: Check Pinning Before 9 September 2026

Twilio says the end-user TLS certificate for all REST API endpoints will rotate on 9 September 2026. Most customers using normal platform trust chains or Twilio Helper Libraries should not need to act, but environments that pin the current leaf certificate or manage certificate trust manually can fail after rotation. The practical preflight is to find manual pinning or custom trust assumptions, test the official tls-test endpoint from every important runtime path, record the result, and remove brittle leaf-certificate dependencies before the cutover.

Open answer

Azure · Computer Vision · API retirement

Azure Computer Vision API Retirement: Prepare Before 13 September 2026

Microsoft lists Azure Computer Vision API versions 1.0, 2.0, 2.1, 3.0 and 3.1 for retirement on 13 September 2026. Teams should identify every endpoint and SDK call that still depends on those versions, map each used feature to a supported replacement, and replay representative non-sensitive image cases against the replacement before cutover. The acceptance check should compare fields, errors, thresholds and product behaviour rather than assuming a version bump is semantically identical.

Open answer

Twilio · Functions Classic · migration

Twilio Functions Classic Migration: Preserve Runtime and Webhook Parity in 2026

Twilio says customers will no longer be able to create new Functions Classic functions and assets from 13 September 2026, and active Classic functions are scheduled for automatic migration between 14 September and 26 October 2026. Twilio plans to preserve URLs, function and asset names, environment variables and deployed code, but teams should still record a before-state and verify critical webhook, runtime, dependency and environment behaviour after migration so a preserved configuration is not mistaken for preserved application behaviour.

Open answer

Cloudflare · API auth · Service Key EOL

Cloudflare Service Key EOL: Move API Callers to Scoped Tokens Before 30 September 2026

Cloudflare says Service Key authentication is deprecated and X-Auth-User-Service-Key will stop working on 30 September 2026. The replacement is a scoped API Token. A safe migration starts by finding every caller that still uses the legacy header, identifying the minimum permissions required by each caller, creating replacement tokens inside Cloudflare, updating the caller without exposing the token to external tooling, and replaying read-only or synthetic acceptance requests before the legacy credential path disappears.

Open answer

HubSpot · private apps · Service Keys

HubSpot Legacy Private-App Creation Sunset: Choose Service Key or Project App

HubSpot says new legacy private-app creation is disabled on 28 September 2026 for accounts created on or after that date and on 26 October 2026 for older accounts. Existing legacy private apps continue to work. For new system-to-system integrations that do not need webhooks, HubSpot directs customers toward Service Keys; integrations that need webhooks should use the Projects-based app path instead. The migration decision therefore starts with the integration capability, not with blindly converting every existing private app.

Open answer

Web tables · CSV · local browser workflow

Extract an HTML Table to CSV Locally Without Uploading the Page

Use Solarc Web Table Extractor on the page you are viewing, invoke it only on that active tab, choose the detected visible table or repeated structure, inspect the cleaned preview, then copy TSV or export CSV or XLSX locally. The current v0.1 builds do not send the inspected page, extracted rows or export files to Solarc Labs or a third-party scraping service. The tool is deliberately bounded: it does not automate login, pagination, infinite scrolling, CAPTCHA bypass or anti-bot evasion, and it only works with content that has already rendered into the DOM.

Open answer