2 Remove Virus

EU begins enforcing rapid cyber incident reporting for digital products

Technology manufacturers selling connected products in the European Union now face strict deadlines for reporting serious cybersecurity incidents and vulnerabilities that are actively being exploited.

 

 

New reporting requirements under the EU Cyber Resilience Act (CRA) became applicable on September 11, 2026. Manufacturers must provide an initial warning within 24 hours after becoming aware of certain security events affecting products with digital elements.

The rules cover two main situations. Vulnerabilities for which there is reliable evidence of active exploitation by attackers and severe incidents affecting the security of a digital product.

Products covered by the CRA include a broad range of hardware and software made available on the EU market. The framework can apply to applications, computer programs, firmware, connected consumer electronics, industrial Internet of Things equipment and components integrated into other connected products.

The reporting process does not end with the first 24-hour warning. Manufacturers must provide a more detailed notification within 72 hours of becoming aware of the issue. For an actively exploited vulnerability, a final report is required no later than 14 days after a corrective or mitigating measure becomes available.

Severe incidents follow a different final deadline. Manufacturers have one month after submitting the 72-hour notification to provide the final report.

To manage the process, the European Union Agency for Cybersecurity (ENISA) has launched a Single Reporting Platform. Companies can use the system to submit one notification rather than separately reporting the same event to multiple national authorities.

The manufacturer selects the appropriate national Computer Security Incident Response Team acting as coordinator when submitting a report. The notification is simultaneously made available to ENISA, while relevant information can then be distributed to other national teams where the affected product is available.

The obligations can also affect companies based outside the European Union if they make covered digital products available on the EU market.

The CRA reporting system is designed to give authorities earlier information about vulnerabilities that attackers are already exploiting and serious security incidents that could put users at risk. It also creates significantly tighter timelines for manufacturers that may previously have handled such disclosures primarily through internal procedures.

Companies may simultaneously face obligations under other European rules, including NIS2 or the General Data Protection Regulation, depending on the circumstances. Reporting an event under the CRA does not automatically replace those separate requirements.

The September deadline represents an early stage in the rollout of the Cyber Resilience Act. Most of the legislation’s wider requirements, including obligations covering the cybersecurity design, maintenance and updating of digital products, will become applicable on December 11, 2027.