EU Cyber Resilience Act reporting obligations become enforceable on September 11
The European Union's Cyber Resilience Act (CRA) begins enforcing its incident and vulnerability reporting requirements on September 11, 2025, ahead of the full compliance deadline of December 11, 2027. Manufacturers of 'products with digital elements' must now report actively exploited vulnerabilities within 24 hours, provide fuller notifications within 72 hours, and submit final reports within 14 days to a month. Non-compliance with reporting rules can result in fines of up to €15 million or 2.5% of global annual turnover. Pure browser-based SaaS products generally fall outside CRA scope and under NIS2 instead, but companies shipping installable components such as desktop apps, SDKs, browser extensions, or on-premise agents are likely covered. Security experts warn that many B2B SaaS firms may unknowingly fall within scope due to supplementary installable tools alongside their core web products.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in