A new stage of the European Union’s rules on the security of digital products began on 11 September 2026. This is not the full application of the Cyber Resilience Act (CRA). It is the start of the reporting duties in Regulation (EU) 2024/2847. Manufacturers of products with digital elements made available on the Union market must now notify actively exploited vulnerabilities and severe incidents that affect the security of those products. The regulation will generally apply from 11 December 2027.
The most visible change is how quickly the first warning must be sent. For an actively exploited vulnerability, a manufacturer must submit an early warning without undue delay and in any event within 24 hours of becoming aware of it. That deadline is for the warning, not for a fix. Within 72 hours of becoming aware of the vulnerability, a fuller notification is required. Where the information is available, it must include general details of the affected product, the nature of the vulnerability and of the exploitation, corrective or mitigating measures taken, and measures users can take where they exist.
The regulation defines an actively exploited vulnerability as a vulnerability for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner. The mandatory duty discussed here does not cover every software flaw that is discovered. A final report on an actively exploited vulnerability is due no later than 14 days after a corrective or mitigating measure becomes available. It must describe the vulnerability in more detail, including severity and impact, set out the security update or other measures made available, and, where the information exists, identify a malicious actor that has exploited or continues to exploit it.
Similar rules apply to severe incidents affecting the security of products with digital elements. An early warning is due within 24 hours of the manufacturer becoming aware of the incident. Within 72 hours, an incident notification must provide available information on the nature of the incident, an initial assessment, and corrective or mitigating measures. The final report on a severe incident is due within one month after that 72-hour notification.
Reports go through the CRA Single Reporting Platform, established and maintained by the European Union Agency for Cybersecurity (ENISA). The design is a single submission rather than repeated filings to several authorities. The notification is addressed to the Computer Security Incident Response Team (CSIRT) designated as coordinator for the manufacturer and, under the regulation, is also made available to ENISA. The coordinating CSIRT then shares relevant information with other CSIRTs in Member States where the product has been made available. In exceptional cases, dissemination to other CSIRTs may be delayed on justified cybersecurity grounds, because technical details of an already exploited vulnerability can create further risk if they are spread too early or too widely.
The duties are not limited to conventional software. The CRA uses the broader concept of “products with digital elements”: in-scope hardware and software whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network. The Commission points to examples ranging from applications and computer programmes to connected devices. The relevant test is not whether the company is headquartered in the EU. It is whether the products concerned are made available on the Union market and what the regulation requires of the economic operators involved.
The reporting obligations that started on 11 September 2026 apply to products with digital elements made available on the Union market, including products placed on the market before full application in December 2027. Implementation is still phased. Provisions on notification of conformity assessment bodies began applying on 11 June 2026. Mandatory reporting of actively exploited vulnerabilities and severe incidents began on 11 September 2026. The main remaining CRA requirements, including design, maintenance and CE-marking duties tied to the regulation, are due to apply generally from 11 December 2027.
For authorities, the system is meant to give ENISA and national incident-response teams a faster view of security problems that are already being used in attacks. For manufacturers, the 24-hour early-warning deadline means internal processes have to be in place before an incident occurs. For users, the wider aim of the regulation is that cybersecurity is treated across the product lifecycle and that vulnerabilities are handled when they are found. 11 September 2026 is therefore a central implementation milestone, not the date on which the entire Cyber Resilience Act became mandatory.
Sources consulted: Cyber Resilience Act - Reporting obligations | Shaping Europe’s digital future; Safer and more secure digital products | European Commission; Regulation (EU) 2024/2847 (Cyber Resilience Act) | EUR-Lex
Image credit: © European Union, 2023, CC BY 4.0. Still from the official clip “EU Cyber Resilience Act, better protection for smart devices” (EU Audiovisual Service, I-244232). Original source: https://audiovisual.ec.europa.eu/en/video/I-244232. Image resized from 1920×1080.
0 Comments
No comments on this article yet. Be the first!