As cited
Copy frozen at (site build).
regulatory
EU's Cyber Resilience Act starts the 24-hour vulnerability clock
The European Union's Cyber Resilience Act (CRA) mandatory vulnerability reporting obligations took effect September 11, 2026, requiring manufacturers of products with digital elements sold in the EU to report actively exploited vulnerabilities within 24 hours to cybersecurity authorities and provide detailed notifications within 72 hours. Manufacturers must file reports through ENISA's Single Reporting Platform to the coordinating computer security incident response team (CSIRT), with maximum fines reaching 15 million euros or 2.5 percent of annual turnover for non-compliance. The reporting deadlines aim to accelerate incident response and force manufacturers to maintain comprehensive understanding of their software supply chains and dependencies throughout product lifecycles, with most remaining CRA provisions taking effect December 11, 2027.
Why it matters: Manufacturers of any product with digital elements sold in the EU must immediately establish or verify vulnerability detection and incident response workflows to meet the 24-hour reporting clock starting now, or face maximum fines; compliance teams should prioritize mapping how the CRA overlaps with other Digital Decade regulations including NIS2, DORA, and the artificial intelligence (AI) Act.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
regulatory
EU's Cyber Resilience Act starts the 24-hour vulnerability clock
The European Union's Cyber Resilience Act (CRA) mandatory vulnerability reporting obligations took effect September 11, 2026, requiring manufacturers of products with digital elements sold in the EU to report actively exploited vulnerabilities within 24 hours to cybersecurity authorities and provide detailed notifications within 72 hours. Manufacturers must file reports through ENISA's Single Reporting Platform to the coordinating computer security incident response team (CSIRT), with maximum fines reaching 15 million euros or 2.5 percent of annual turnover for non-compliance. The reporting deadlines aim to accelerate incident response and force manufacturers to maintain comprehensive understanding of their software supply chains and dependencies throughout product lifecycles, with most remaining CRA provisions taking effect December 11, 2027.
Why it matters: Manufacturers of any product with digital elements sold in the EU must immediately establish or verify vulnerability detection and incident response workflows to meet the 24-hour reporting clock starting now, or face maximum fines; compliance teams should prioritize mapping how the CRA overlaps with other Digital Decade regulations including NIS2, DORA, and the artificial intelligence (AI) Act.
- Source published
- First seen by Cybersecurity Tracker