The European Union is moving into a new phase of its Cyber Resilience Act (CRA), with mandatory cybersecurity reporting requirements starting on 11 September 2026. The rules require manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents that affect the security of their products. The change is an important step in the EU’s wider effort to make connected products safer and improve how quickly cybersecurity threats are identified and handled. The CRA itself entered into force on 10 December 2024, while its main requirements will apply from 11 December 2027.
Under the new reporting rules, manufacturers must act quickly when they become aware of an actively exploited vulnerability or a severe security incident affecting their product. An early warning must be submitted within 24 hours of becoming aware of the issue. A more detailed notification must then be provided within 72 hours. For actively exploited vulnerabilities, a final report must be submitted no later than 14 days after a corrective or mitigating measure becomes available. For severe incidents, the final report must be submitted within one month of the 72-hour notification.
The reporting process will use the CRA Single Reporting Platform, developed under the responsibility of the European Union Agency for Cybersecurity, known as ENISA. The platform is designed to simplify the process by allowing manufacturers to report through one system instead of separately notifying multiple national authorities. Reports are submitted to the relevant Computer Security Incident Response Team, or CSIRT, in the Member State connected to the manufacturer’s main establishment and are made available to ENISA. The platform is scheduled to become operational when the reporting requirements begin.
The new requirements are also designed to improve cooperation between cybersecurity authorities across the EU. Once a report is received, the relevant CSIRT can share the information with other CSIRTs in Member States where the affected product has been made available. In certain exceptional circumstances, sharing can be delayed when there are justified cybersecurity-related reasons. The EU has also adopted additional rules explaining when such delays can be used. This approach is intended to give authorities faster access to information that may help them respond to vulnerabilities and serious security incidents affecting products across different countries.
Manufacturers will also have responsibilities toward users when an actively exploited vulnerability or severe security incident is discovered. The CRA requires manufacturers to inform affected users, and where appropriate all users, about the vulnerability or incident and provide information about available corrective or risk-reduction measures. The broader regulation also requires manufacturers to manage vulnerabilities throughout the product’s support period and provide security updates where necessary. These requirements are part of the EU’s wider plan to make cybersecurity a normal part of the entire lifecycle of digital products rather than something addressed only after a serious attack.
The European Commission published practical guidance on 27 July 2026 to help manufacturers, developers and businesses understand how to implement the CRA. The guidance explains areas including product scope, support periods, substantial modifications, risk assessments and reporting responsibilities, with additional attention given to smaller businesses. With reporting obligations beginning on 11 September 2026 and the main CRA obligations scheduled for 11 December 2027, companies have entered an important preparation period. The new reporting system represents a major change in how cybersecurity vulnerabilities and severe incidents involving digital products must be reported across the European Union.
Stay alert, and keep your security measures updated!
Source: Follow cybersecurity88 on X and LinkedIn for the latest cybersecurity news