EU Cyber Resilience Act Reporting Rules Now Live: What Developers Must Know
The EU Cyber Resilience Act's (CRA) mandatory vulnerability reporting obligations came into effect on 11 September 2026, applying to any developer or company that commercially supplies software or hardware to the EU market. Under Article 14, manufacturers must notify ENISA and the relevant national CSIRT within 24 hours of discovering an actively exploited vulnerability, follow up with a detailed notification within 72 hours, and submit a final report within 14 days of a fix being available. The rules apply equally to individual developers selling apps or games as to large corporations, regardless of where the seller is based. Commercially active is defined broadly to include paid products, ad-supported software, and data-monetised services, not just direct sales. Broader CRA requirements — including SBOM documentation, CE marking, and a minimum five-year security support period — do not take effect until 11 December 2027.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in