EU Cyber Resilience Act’s 24-Hour Vulnerability Reporting Mandate Takes Effect

As of September 11, 2026, manufacturers selling digital products in the European Union must report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware of them, and file a full notification within 72 hours, Dark Reading reported, corroborated by the European Commission’s official Cyber Resilience Act reporting page. Non-compliance can carry fines of up to €15 million.

The reporting mandate is the first Cyber Resilience Act obligation to take effect, well ahead of the regulation’s full enforcement date in December 2027.

Why it matters: The 24-hour reporting window is significantly tighter than most manufacturers’ existing vulnerability-disclosure processes, and applies to any company selling connected digital products into the EU market — including physical security hardware vendors such as camera, access control and sensor manufacturers — making early compliance planning a genuine operational deadline rather than a distant regulatory milestone.

Source: Dark Reading, September 11, 2026, corroborated by the European Commission’s official CRA reporting page.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *