As of September 11, 2026, manufacturers selling digital products in the European Union must report actively exploited vulnerabilities to ENISA within 24 hours of becoming aware of them, and file a full notification within 72 hours, Dark Reading reported, corroborated by the European Commission’s official Cyber Resilience Act reporting page. Non-compliance can carry fines of up to €15 million.
The reporting mandate is the first Cyber Resilience Act obligation to take effect, well ahead of the regulation’s full enforcement date in December 2027.
Why it matters: The 24-hour reporting window is significantly tighter than most manufacturers’ existing vulnerability-disclosure processes, and applies to any company selling connected digital products into the EU market — including physical security hardware vendors such as camera, access control and sensor manufacturers — making early compliance planning a genuine operational deadline rather than a distant regulatory milestone.
Source: Dark Reading, September 11, 2026, corroborated by the European Commission’s official CRA reporting page.

Leave a Reply