Global Tech Manufacturers Face September 11 Deadline to Report Exploited Vulnerabilities Under EU Cyber Resilience Act
Starting September 11, 2026, the EU Cyber Resilience Act will require manufacturers to report actively exploited vulnerabilities within 24 hours. The mandate applies retroactively to all products currently on the market, forcing a massive shift in how the tech industry handles software supply chain security.
- Compliance & Legal Advisors
- Focuses on the strict timelines, retroactive scope, and the severe financial penalties for non-compliance.
- Security Tooling Vendors
- Argues that meeting the 24-hour deadline requires a shift from static scanning to continuous, automated vulnerability monitoring.
- EU Regulators
- Views the mandate as a necessary intervention to secure the digital supply chain and protect consumers from silent exploits.
What we don’t know
- How ENISA's Single Reporting Platform will perform under the load of a ubiquitous vulnerability triggering thousands of simultaneous reports.
- The exact evidentiary threshold required to prove a malicious actor is actively exploiting a vulnerability in the wild.
- How strictly national CSIRTs will enforce the 24-hour deadline and maximum penalties during the initial months of the mandate.
On September 11, 2026, the European Union will fundamentally change how software vulnerabilities are handled globally. Under the new Cyber Resilience Act (CRA), any manufacturer selling a product with digital elements in the EU must report actively exploited vulnerabilities to authorities within 24 hours. The mandate represents a massive structural win for consumer protection, effectively ending the era where vendors could quietly patch critical flaws months after discovery while leaving users exposed.[1][5]
For years, the tech industry has treated the CRA as a distant 2027 problem, focusing on the law's broader secure-by-design mandates and CE marking requirements. But the reporting requirement arrives 15 months earlier, and it carries the exact same severe penalties: up to €15 million or 2.5% of global annual turnover, whichever is higher.[2][3]
Security vendors are currently flooding the market with "CRA-ready" compliance dashboards, promising automated peace of mind. But the actual text of Article 14 demands operational capability, not just a static Software Bill of Materials (SBOM). You cannot report an active exploit in 24 hours if you do not have continuous, real-time visibility into your deployed code and the threat landscape.[4]
The reporting timeline is strictly staged. When a manufacturer becomes aware of an actively exploited vulnerability, the clock starts immediately. They have 24 hours to submit an early warning to the European Union Agency for Cybersecurity (ENISA) and their national Computer Security Incident Response Team (CSIRT).[1][8]
Within 72 hours, a detailed technical notification must follow, outlining the nature of the vulnerability and the corrective measures planned. Finally, no later than 14 days after a patch or corrective measure is available, the manufacturer must submit a comprehensive final report detailing the root cause and mitigation.[2][7]
The scope of "products with digital elements" is intentionally broad. It covers everything from industrial programmable logic controllers (PLCs) and smart home IoT devices to operating systems and mobile applications. Pure Software-as-a-Service (SaaS) platforms are generally excluded, but any software distributed to run on a user's machine falls squarely under the regulation.[7]
The most significant, and least advertised, aspect of the September 2026 deadline is its retroactive scope. The obligation does not just apply to new products shipped after the deadline. It applies to any product currently on the EU market, including legacy systems deployed years ago that are still in use.[5]
The most significant, and least advertised, aspect of the September 2026 deadline is its retroactive scope.
Legal and compliance experts point out that this transforms technical debt into immediate legal liability. Products relying on end-of-life frameworks—such as older versions of AngularJS or Spring—are now ticking compliance clocks. If an exploit hits a legacy component, the manufacturer must detect and report it just as quickly as a flaw in their flagship release.[6]
Alongside vulnerabilities, the law also mandates reporting for "severe incidents." These are events that compromise the security of the product itself—such as a breach of a manufacturer's build environment or update servers that could allow malicious code to be pushed to end users. For these incidents, the final report is due within one month.[2][8]
The mandate explicitly targets "actively exploited vulnerabilities"—meaning there is reliable evidence that a malicious actor is using the flaw without permission. Routine security patches and vulnerabilities discovered and fixed internally before any exploitation occurs do not trigger the 24-hour reporting requirement.[1][2]
What remains unclear is exactly how ENISA will handle the incoming deluge of data. The Single Reporting Platform (SRP) is mandated to be operational by the September deadline, but large-scale load testing has not yet been publicly validated. There is thin evidence on how the platform will perform when a ubiquitous vulnerability—akin to Log4j—triggers simultaneous 24-hour reports from thousands of vendors.[2]
Despite the operational friction for manufacturers, this mandate is a watershed moment for enterprise security. By forcing a 24-hour disclosure window to national authorities, the CRA empowers CSIRTs to issue rapid ecosystem-wide warnings and coordinate defenses before an exploit can cascade through critical infrastructure.[7][8]
The deadline is already forcing a structural shift in software engineering. To meet the 24-hour window, companies are moving away from point-in-time security scans toward continuous, agentic monitoring systems that map threat intelligence directly to deployed SBOMs.[3][4]
The September 11 deadline is not a suggestion, and the grace period is evaporating. Manufacturers who wait for the broader 2027 enforcement date will find themselves legally exposed.[5]
The capability to detect, assess, and report an active exploit within a single day is no longer a best practice—it is the baseline cost of doing business in Europe. For consumers, it means the software they rely on is about to become significantly more transparent and secure.[8]
- 24 hours
- Early warning deadline
- 72 hours
- Detailed notification deadline
- 14 days
- Final report deadline post-patch
- €15 million
- Maximum non-compliance penalty
- 15 months
- Gap before full 2027 enforcement
Sources
[1]European CommissionEU RegulatorsFrequently Asked Questions on Cyber Resilience Act Single Reporting Platform (CRA SRP)
Read on European Commission →
[2]ElementCompliance & Legal AdvisorsThree Things Manufacturers Get Wrong About the CRA Reporting Obligations
Read on Element →
[3]ArmorCodeSecurity Tooling VendorsResolve EU Cyber Resilience Act (CRA) Compliance Challenges
Read on ArmorCode →
[4]KeysightSecurity Tooling VendorsThe EU Cyber Resilience Act (CRA) imposes a critical deadline on September 11, 2026
Read on Keysight →
[5]CertivoCompliance & Legal AdvisorsEU CRA Vulnerability Reporting: The 24-Hour Rule and Retroactive Scope
Read on Certivo →
[6]HeroDevsSecurity Tooling VendorsEU Cyber Resilience Act reporting obligations take effect September 11, 2026
Read on HeroDevs →
[7]Northwave CybersecuritySecurity Tooling VendorsHow to prepare for the first EU Cyber Resilience Act deadline
Read on Northwave Cybersecurity →
[8]DLA PiperCompliance & Legal AdvisorsThe CRA Reporting Framework: Operationalising the 24-Hour Window
Read on DLA Piper →
Comments
Every angle. Every day.
Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.


