top of page

EU Cyber Resilience Act Starts 24-Hour Security Reporting Clock

50 minutes ago
2 min read

Manufacturers selling connected hardware and software in the European Union now face strict cybersecurity reporting deadlines under the EU Cyber Resilience Act.


The requirements took effect on September 11, 2026, and apply to manufacturers of “products with digital elements” made available in the EU, including companies headquartered outside the bloc. Covered businesses must report actively exploited vulnerabilities and severe security incidents affecting their products through the EU’s Cyber Resilience Act Single Reporting Platform.


Under the Cyber Resilience Act reporting rules, a manufacturer must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or qualifying incident. A more detailed notification follows within 72 hours.


For exploited vulnerabilities, a final report is due no later than 14 days after a corrective or mitigating measure becomes available. For severe security incidents, the final report must be submitted within one month of the 72-hour notification.


The compressed timeline could expose weaknesses in how companies coordinate vulnerability intelligence, product security, legal reviews and regulatory disclosures.


“For many organizations, these reporting requirements will be the first real test of operational readiness,” said Louise Horton, government affairs lead at NCC Group. “Success will depend on having mature vulnerability management processes, visibility across products and dependencies, and the ability to identify, assess and report security issues quickly and accurately.”


The rules do not apply only to European companies. Any covered manufacturer placing a digital product on the EU market may fall within the regulation’s reach.


“Today, the Cyber Resilience Act (CRA) stops being a document companies plan around and becomes a clock they have to answer to,” said Nikhil Gupta, founder and CEO of ArmorCode. “That’s not 24 business hours; it’s 24 hours, full stop, regardless of time zone or weekend.”


Gupta said many organizations already possess tools capable of identifying vulnerabilities. The harder problem is combining information scattered across security information and event management systems, threat intelligence feeds, asset inventories, scanner results and software bills of materials quickly enough to support a regulatory filing.


“A 24-hour reporting window leaves no room for manual coordination,” Gupta said. “If your process for confirming exploitation and drafting a notification depends on a security analyst finding the right spreadsheet and looping in product, legal, and compliance by email, you will lose hours you don't have before you've even started writing the report.”


Most remaining Cyber Resilience Act requirements become applicable on December 11, 2027. The reporting mandate’s earlier arrival gives manufacturers their first operational test of whether product security programs can satisfy the EU’s broader secure-by-design ambitions.

bottom of page