EU Cyber Resilience Act reporting obligations now active for software vendors
The European Union's Cyber Resilience Act imposes new reporting duties on manufacturers of products with digital elements, effective since September 11, 2026. Vendors must report actively exploited vulnerabilities within 24 hours of becoming aware and submit detailed notifications within 72 hours. The regulations apply to both new products and those already on the EU market, with non-EU manufacturers reporting through authorized representatives. ENISA has launched a Single Reporting Platform for submissions, and serious breaches can result in substantial fines.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in