EU Cyber Resilience Act Mandates 24-Hour Vulnerability Reporting From September 2026
The EU Cyber Resilience Act's Article 14 reporting obligations became enforceable on 11 September 2026, more than a year ahead of the regulation's full application date of December 2027. Manufacturers of hardware and software products with digital elements must now notify the ENISA Single Reporting Platform within 24 hours of becoming aware of an actively exploited vulnerability or a severe security incident. A more detailed follow-up notification is required within 72 hours, covering affected products, assessed impact, and any mitigation steps taken or planned, with a final report due after remediation. The obligation applies to both new and existing products already circulating on the EU market, and non-EU manufacturers are also covered under the regulation. Manufacturers must additionally inform affected users about the risk and available mitigations, which is a separate requirement from the authority notification duty.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in