EU Cyber Resilience Act Begins Enforcing Reporting Rules on September 11, 2026
The European Union's Cyber Resilience Act, its first broad cybersecurity law covering all digital products sold in the EU, begins enforcing its initial obligations on September 11, 2026. Starting that date, developers and companies must report actively exploited vulnerabilities to EU cybersecurity agency ENISA within 24 hours and submit full incident reports within 72 hours. Critically, these reporting rules apply to software already on the market, not just new products shipped after the deadline, catching many companies off guard. Most organizations currently lack the internal processes, designated personnel, and documentation workflows required to comply with these timelines. The full set of product and process requirements — including secure-by-default design, Software Bills of Materials, and CE marking — does not take effect until December 2027.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in