CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7082

As cited

Copy frozen at (site build).

regulatory

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

The European Union's Cyber Resilience Act (CRA) mandatory vulnerability reporting obligations took effect September 11, 2026, requiring manufacturers of products with digital elements sold in the EU to report actively exploited vulnerabilities within 24 hours to cybersecurity authorities and provide detailed notifications within 72 hours. Manufacturers must file reports through ENISA's Single Reporting Platform to the coordinating computer security incident response team (CSIRT), with maximum fines reaching 15 million euros or 2.5 percent of annual turnover for non-compliance. The reporting deadlines aim to accelerate incident response and force manufacturers to maintain comprehensive understanding of their software supply chains and dependencies throughout product lifecycles, with most remaining CRA provisions taking effect December 11, 2027.

Why it matters: Manufacturers of any product with digital elements sold in the EU must immediately establish or verify vulnerability detection and incident response workflows to meet the 24-hour reporting clock starting now, or face maximum fines; compliance teams should prioritize mapping how the CRA overlaps with other Digital Decade regulations including NIS2, DORA, and the artificial intelligence (AI) Act.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

regulatory

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

The European Union's Cyber Resilience Act (CRA) mandatory vulnerability reporting obligations took effect September 11, 2026, requiring manufacturers of products with digital elements sold in the EU to report actively exploited vulnerabilities within 24 hours to cybersecurity authorities and provide detailed notifications within 72 hours. Manufacturers must file reports through ENISA's Single Reporting Platform to the coordinating computer security incident response team (CSIRT), with maximum fines reaching 15 million euros or 2.5 percent of annual turnover for non-compliance. The reporting deadlines aim to accelerate incident response and force manufacturers to maintain comprehensive understanding of their software supply chains and dependencies throughout product lifecycles, with most remaining CRA provisions taking effect December 11, 2027.

Why it matters: Manufacturers of any product with digital elements sold in the EU must immediately establish or verify vulnerability detection and incident response workflows to meet the 24-hour reporting clock starting now, or face maximum fines; compliance teams should prioritize mapping how the CRA overlaps with other Digital Decade regulations including NIS2, DORA, and the artificial intelligence (AI) Act.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary