Manufacturers of connected products sold across the European Union woke up on 11 September 2026 to a legal clock that starts ticking the moment they learn that someone is actively exploiting a flaw in their software or hardware. The Cyber Resilience Act, formally Regulation (EU) 2024/2847, entered into force on 10 December 2024, but its reporting obligations only became applicable on that September day, pulling a vast range of everyday devices, from smart thermostats and home routers to industrial sensors and licensed software, into one disclosure regime.
The European Commission announced that from 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents that have an impact on the security of their products, with a 24-hour early warning to the EU Agency for Cybersecurity and the relevant national computer security incident response team, known as a CSIRT. A full notification must follow within 72 hours, and a final report must arrive no later than 14 days after a corrective or mitigating measure is available for an actively exploited vulnerability, or within one month for a severe incident.
The rules are not limited to new releases. Article 69(3) extends the Article 14 reporting duty to all in-scope products already on the EU market, including hardware shipped years before the regulation existed and software licensed before it, even though a general grandfathering rule otherwise covers pre-2027 products. Manufacturers are not required to retrospectively report active exploitation they were already aware of before 11 September 2026.
The Cyber Resilience Act is the EU's horizontal regulatory framework imposing mandatory cybersecurity requirements for products with digital elements throughout their lifecycle. Its main obligations, including secure by design engineering, CE marking, conformity assessments and formal Software Bill of Materials production, apply from 11 December 2027. Reporting travels on a much faster track, and so does the pressure on engineering, legal and communications teams that must document what they knew and exactly when they knew it.
Key Facts
ENISA launched the initial operating capability of the CRA Single Reporting Platform on 11 September 2026, the online tool through which manufacturers and open-source software stewards meet their new obligations. Manufacturers report once: the coordinating national CSIRT initially receives the notification and disseminates it to other relevant CSIRTs in member states where the affected product is available, while the notification is simultaneously made available to ENISA. The platform had no API at launch, according to Tech Times, which means submissions must be made manually through the web portal.
The trigger is narrow and specific. An actively exploited vulnerability is defined in Article 3 as one for which there is reliable evidence that a malicious actor has exploited it in a system without the permission of the system owner. Slaughter and May noted on 11 September 2026 that vulnerabilities found in routine security testing are not reportable unless there is evidence of exploitation. A severe incident is one that negatively affects the product's ability to protect the confidentiality, integrity or availability of sensitive data or functions, or that is capable of leading to the execution of malicious code in the product or in the user's network.
The clock does not start from a CVE identifier or a CVSS score, noze.it reported on 11 September 2026, but from reliable evidence that somebody is exploiting the vulnerability. European Commission guidance of 27 July 2026 defines awareness as the point when an initial assessment reaches reasonable certainty about active exploitation, which is why manufacturers must keep separate timestamped records, since the reporting platform alone cannot document compliance.
Penalties are steep. Tech Times reported on 11 September 2026 that fines for non-compliance can reach EUR 15 million, about USD 17.4 million, or 2.5% of a company's global annual turnover, whichever is higher. noze.it noted on 11 September 2026 that Article 64 sets that ceiling for breaches of Articles 13 and 14, while adding that the textual reading of Article 71 suggests the duty to report is already enforceable from 11 September 2026 even though the penalty apparatus follows the general 11 December 2027 calendar.
Article 71 sets a counterintuitive phase-in schedule. The regulation shall apply from 11 December 2027, but Article 14 applies from 11 September 2026 and Chapter IV, covering Articles 35 to 51, applied from 11 June 2026. Reporting obligations will also extend to open-source software stewards involved in developing products with digital elements from 11 December 2027 under Article 24(3). Non-EU manufacturers must designate an authorized representative in the union, and advance registration on the platform is the critical operational step for meeting all three reporting clocks.
Analysis
What this really means is that the European Union has converted vulnerability disclosure from a voluntary professional norm into a legal duty measured in hours, and the burden falls hardest on the manufacturers with the least mature security operations. A company that has never run a formal incident response process now has to detect active exploitation, assess it, decide whether it meets the legal threshold, and file a structured early warning to both a national CSIRT and ENISA within a single working day. ENISA has tried to soften the transition by publishing FAQs, user manuals, tutorial videos, a platform glossary, a factsheet and a dedicated help desk, but guidance is not the same as capability.
The numbers behind the policy explain the urgency. ENISA Executive Director Juhan Lepassaar said that vulnerabilities in digital products are often exploited by threat actors to subvert or hamper critical services such as healthcare, energy, transport or telecommunications, and that streamlined reporting and sharing of information helps build a more resilient Digital Single Market. Tech Times cited the Aisuru botnet, which grew by 2025 to launch denial of service attacks exceeding 29.7 Tbps from an estimated 300,000 to 700,000 compromised consumer routers, digital video recorders and IP cameras. Those are precisely the kinds of low-cost, widely sold devices the reporting duty is designed to illuminate.
The bigger picture here is a shift in where the cost of insecurity sits. Because the early warning for a severe incident must state at minimum whether the incident is suspected to result from unlawful or malicious acts, manufacturers cannot simply forward a scanner alert; they must make a judgement under uncertainty, publish it to regulators, and refine it within 72 hours. Slaughter and May observed on 11 September 2026 that the obligations continue after a product's support period ends, turning end-of-life planning into a compliance question. For two decades the default was that users absorbed the damage from flawed connected products, and the Act now moves part of that cost back to the entity that designed the device.
Why It Matters
For buyers, the reporting regime creates a new signal. A manufacturer that can meet a 24-hour deadline reliably is demonstrating an incident response capability, not just good intentions, and that capability is now auditable through filings that national market surveillance authorities can scrutinise. Procurement teams that previously asked for a security questionnaire can now ask a sharper question: how fast does this vendor report, and can it prove the timestamp?
For the open-source ecosystem, the effect is delayed but real. Article 24(3) brings open-source software stewards within the reporting obligations from 11 December 2027, which means volunteer-led projects and foundations that steward code used inside commercial products will need a process for receiving, triaging and reporting exploitation evidence. That is a heavy expectation for organisations without legal departments.
For regulators, the platform is the test. The Commission published practical guidance to help manufacturers, developers and businesses meet their obligations, and national market surveillance authorities will ensure enforcement. If the Single Reporting Platform cannot scale, or if early warnings arrive without the context investigators need, the regime will generate paperwork rather than resilience. The absence of an API at launch suggests the first months will be a learning period for everyone involved.
Next Up
Attention now turns to how the first wave of notifications is handled and to the national enforcement gaps that remain. The Italian picture illustrates the wider problem: noze.it reported on 11 September 2026 that Law 36 of 17 March 2026 contains a delegation to adapt national legislation, but the delegated decree formally identifying the market surveillance authority and setting the national penalty regime had not been published as of that date. Until member states finish that work, the duty to report will be clearer than the consequences of failing to do so.
The next hard deadline on the calendar is 11 December 2027, when the Act's main cybersecurity requirements, CE marking and conformity assessment duties take effect and when open-source software stewards join the reporting regime. Between now and then, manufacturers have roughly fifteen months to move from manual portal submissions to something that resembles a repeatable compliance process. The 24-hour clock is already running.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.