EU Cyber Resilience Act Mandatory Vulnerability Reporting Begins September 11
The European Union's Cyber Resilience Act (CRA) activates its mandatory incident reporting requirements on September 11, 2026, affecting software makers and device manufacturers selling products in the EU. Under the new rules, companies must issue an early warning within 24 hours of discovering an actively exploited vulnerability, followed by a formal notification within 72 hours and a final report within 14 days. Reports must be submitted to the relevant national CSIRT and to ENISA through a Single Reporting Platform, with the clock starting the moment a team becomes aware of an issue. The regulation targets any manufacturer placing a product with digital elements on the EU market, including apps, firmware, and connected devices, though pure SaaS services generally fall under the separate NIS2 directive. Full CRA compliance, including CE marking, is not required until December 2027, but the reporting obligations take effect immediately this Friday.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in