Skip to main content
Cyber Resilience ActPolicy Enforcement· 4 min read· in Technology

EU Cyber Resilience Act Reporting Obligations Take Effect for Actively Exploited Vulnerabilities

Manufacturers selling digital products in the European Union must now report actively exploited vulnerabilities within 24 hours, as the Cyber Resilience Act's first major enforcement milestone takes effect.

By Beatriz Santos

Security Vendors 35%Legal & Compliance Teams 35%European Regulators 30%
Security Vendors
Cybersecurity providers emphasizing the need for continuous visibility to meet the new 24-hour deadlines.
Legal & Compliance Teams
Advisors focused on the immediate regulatory exposure and the nuances of the non-retroactive reporting mandate.
European Regulators
Authorities prioritizing rapid incident response and consumer protection across the EU single market.

Perspectives this story doesn't cover

  • Open-Source Maintainers
  • Enterprise Procurement Teams

Why this matters

Manufacturers selling digital products in the European Union now face a strict 24-hour deadline to report actively exploited vulnerabilities, backed by fines of up to €15 million. The immediate enforcement forces companies to overhaul their security monitoring 15 months before the rest of the law takes effect.

Enterprise software vendors and hardware manufacturers have largely treated the European Union’s Cyber Resilience Act as a 2027 compliance problem. That timeline is no longer accurate. As of September 11, 2026, the CRA’s Article 14 reporting obligations are legally enforceable, requiring any manufacturer with digital products on the EU market to disclose actively exploited vulnerabilities to regulators within 24 hours of discovery. The European Union Agency for Cybersecurity (ENISA) activated its Single Reporting Platform on Wednesday morning, shifting the legislation from a theoretical framework into an active regulatory mechanism.[1][3][4]

The CRA was formally adopted to address the chronic lack of security updates in connected devices, but its rollout is staggered. While the core cybersecurity-by-design requirements and CE marking mandates do not apply until December 11, 2027, the vulnerability disclosure window was fast-tracked by 15 months. The rules apply to any hardware or software product with digital elements sold in the EU, regardless of where the manufacturer is headquartered.[2][4]

The reporting mechanism imposes one of the tightest disclosure windows in global cybersecurity regulation. When a manufacturer becomes aware of an actively exploited vulnerability or a severe incident affecting their product, they must submit an early warning through the ENISA Single Reporting Platform within 24 hours. A full technical notification is required within 72 hours. Finally, the manufacturer must submit a conclusive report no later than 14 days after a corrective measure—such as a software patch—becomes available.[1][3]

Manufacturers must adhere to a strict three-phase reporting timeline once an active exploit is discovered.

The mandate is not retroactive, meaning companies do not need to report exploits they knew about before the deadline. As legal analysts at Goodwin noted, "A manufacturer does not need to report an event if it was already aware of the active exploitation or incident before 11 September 2026." However, the obligation applies immediately to any new discovery, even if the underlying flaw existed in the product for years.[2]

The mandate is not retroactive, meaning companies do not need to report exploits they knew about before the deadline.

Failure to meet these deadlines carries severe financial consequences. According to the regulatory framework, non-compliance with the reporting obligations can trigger administrative fines of up to €15 million, or 2.5% of a company’s total worldwide annual turnover for the preceding financial year, whichever figure is higher. National Computer Security Incident Response Teams (CSIRTs) across member states will coordinate the intake and enforcement alongside ENISA.[2][4]

The immediate enforcement has created a stark dividing line between commercial manufacturers and the open-source community. While commercial entities are now on the clock, open-source software stewards are explicitly exempt from the September 2026 deadline, granting them a temporary reprieve from the strict reporting windows.[1]

National CSIRTs across EU member states will coordinate the intake of vulnerability reports alongside ENISA.

The European Commission's framework clarifies that open-source software stewards do not carry a legal reporting burden until December 11, 2027. However, the mandate for commercial entities is absolute. "As a rule, if an organization distributes its products anywhere in the EU, and if its products have any kind of network connectivity, then that organization is subject to the CRA," noted Dark Reading, highlighting that companies do not need to be physically based in Europe to face the new reporting windows.[1][4]

Security vendors are already positioning the deadline as a catalyst for overhauling corporate vulnerability management. The practical challenge for enterprise teams is no longer drafting policy, but building the continuous visibility required to separate theoretical exposures from active exploits. If a company cannot definitively prove when it first learned of an exploit, it cannot prove it met the 24-hour reporting window.[3][4]

The activation of the ENISA Single Reporting Platform transforms European market access requirements immediately. Procurement teams and enterprise buyers are expected to use the new reporting baseline as a standard contractual requirement, forcing manufacturers to instrument their software supply chains for rapid disclosure. With the platform now live and the 24-hour countdowns enforceable, the grace period for product security in the European market has officially expired.[4]

Viewpoints in depth

Security Vendors

Cybersecurity providers emphasize the operational shock of a 24-hour disclosure window.

For commercial hardware and software vendors, the September 2026 deadline represents a severe operational hurdle. The 24-hour early warning requirement leaves almost no margin for error, forcing companies to implement continuous visibility tools that can instantly distinguish between a theoretical code flaw and an active exploit. Because fines can reach 2.5% of global turnover, security vendors are advising engineering departments to instrument their software supply chains with immutable timestamps, ensuring the company can prove exactly when it first learned of a breach.

Legal & Compliance Teams

Advisors focus on the strict, non-retroactive nature of the new regulatory mandate.

Legal analysts stress that while the CRA reporting obligations are immediate, they are not retroactive. Companies are not required to disclose active exploits they were already aware of prior to September 11, 2026. However, the moment a new exploit is discovered—even if the underlying vulnerability has existed in the product for years—the 24-hour clock begins. This nuance places an immense burden on compliance teams to meticulously document the exact time of discovery to defend against potential regulatory audits.

European Regulators

Authorities view the reporting window as a critical mechanism for securing the single market.

From the perspective of the European Commission and national cybersecurity agencies, the fast-tracked reporting obligations are necessary to stop the cascading effects of supply chain attacks. By forcing manufacturers to disclose active exploits within 24 hours, regulators aim to drastically reduce the window in which hackers can compromise secondary targets. The activation of the Single Reporting Platform allows national CSIRTs to coordinate threat intelligence across borders instantly, shifting the EU's cybersecurity posture from reactive patching to proactive threat containment.

Key points

  • The EU Cyber Resilience Act's vulnerability reporting obligations are legally enforceable as of September 11, 2026.
  • Manufacturers must report actively exploited vulnerabilities to regulators within 24 hours of discovery.
  • The mandate applies to all digital products on the EU market, backed by fines of up to €15 million.
  • Open-source software stewards are exempt from the reporting requirements until December 2027.

Sources

Source coverage

4 outlets

3 viewpoints surfaced

Security Vendors 35%Legal & Compliance Teams 35%European Regulators 30%
  1. [1]European CommissionEuropean Regulators

    Cyber Resilience Act - Reporting obligations

    Read on European Commission
  2. [2]GoodwinLegal & Compliance Teams

    Preparing for the EU Cyber Resilience Act: Key Reporting Obligations From 11 September 2026

    Read on Goodwin
  3. [3]ThreatLockerSecurity Vendors

    EU Cyber Resilience Act 24-hour vulnerability reporting begins Sept. 11

    Read on ThreatLocker
  4. [4]Dark ReadingSecurity Vendors

    EU Cyber Resilience Act to Enforce New Reporting Requirements

    Read on Dark Reading

Comments

Stay informed

Every angle. Every day.

Get Technology stories with full source coverage and perspective breakdowns delivered to your inbox.