Skip to main content
Cyber Resilience ActRegulatory DeadlineAug 27, 2026, 1:56 PM· 4 min read· in technology

Global Tech Manufacturers Face September 11 Deadline to Report Exploited Vulnerabilities Under EU Cyber Resilience Act

Starting September 11, 2026, the EU Cyber Resilience Act will require manufacturers to report actively exploited vulnerabilities within 24 hours. The mandate applies retroactively to all products currently on the market, forcing a massive shift in how the tech industry handles software supply chain security.

By Diego Navarro

Compliance & Legal Advisors 40%Security Tooling Vendors 35%EU Regulators 25%
Compliance & Legal Advisors
Focuses on the strict timelines, retroactive scope, and the severe financial penalties for non-compliance.
Security Tooling Vendors
Argues that meeting the 24-hour deadline requires a shift from static scanning to continuous, automated vulnerability monitoring.
EU Regulators
Views the mandate as a necessary intervention to secure the digital supply chain and protect consumers from silent exploits.

What we don’t know

  • How ENISA's Single Reporting Platform will perform under the load of a ubiquitous vulnerability triggering thousands of simultaneous reports.
  • The exact evidentiary threshold required to prove a malicious actor is actively exploiting a vulnerability in the wild.
  • How strictly national CSIRTs will enforce the 24-hour deadline and maximum penalties during the initial months of the mandate.

On September 11, 2026, the European Union will fundamentally change how software vulnerabilities are handled globally. Under the new Cyber Resilience Act (CRA), any manufacturer selling a product with digital elements in the EU must report actively exploited vulnerabilities to authorities within 24 hours. The mandate represents a massive structural win for consumer protection, effectively ending the era where vendors could quietly patch critical flaws months after discovery while leaving users exposed.[1][5]

For years, the tech industry has treated the CRA as a distant 2027 problem, focusing on the law's broader secure-by-design mandates and CE marking requirements. But the reporting requirement arrives 15 months earlier, and it carries the exact same severe penalties: up to €15 million or 2.5% of global annual turnover, whichever is higher.[2][3]

Security vendors are currently flooding the market with "CRA-ready" compliance dashboards, promising automated peace of mind. But the actual text of Article 14 demands operational capability, not just a static Software Bill of Materials (SBOM). You cannot report an active exploit in 24 hours if you do not have continuous, real-time visibility into your deployed code and the threat landscape.[4]

The reporting timeline is strictly staged. When a manufacturer becomes aware of an actively exploited vulnerability, the clock starts immediately. They have 24 hours to submit an early warning to the European Union Agency for Cybersecurity (ENISA) and their national Computer Security Incident Response Team (CSIRT).[1][8]

The mandatory reporting timeline under Article 14 of the Cyber Resilience Act.

Within 72 hours, a detailed technical notification must follow, outlining the nature of the vulnerability and the corrective measures planned. Finally, no later than 14 days after a patch or corrective measure is available, the manufacturer must submit a comprehensive final report detailing the root cause and mitigation.[2][7]

The scope of "products with digital elements" is intentionally broad. It covers everything from industrial programmable logic controllers (PLCs) and smart home IoT devices to operating systems and mobile applications. Pure Software-as-a-Service (SaaS) platforms are generally excluded, but any software distributed to run on a user's machine falls squarely under the regulation.[7]

The most significant, and least advertised, aspect of the September 2026 deadline is its retroactive scope. The obligation does not just apply to new products shipped after the deadline. It applies to any product currently on the EU market, including legacy systems deployed years ago that are still in use.[5]

The most significant, and least advertised, aspect of the September 2026 deadline is its retroactive scope.

Legal and compliance experts point out that this transforms technical debt into immediate legal liability. Products relying on end-of-life frameworks—such as older versions of AngularJS or Spring—are now ticking compliance clocks. If an exploit hits a legacy component, the manufacturer must detect and report it just as quickly as a flaw in their flagship release.[6]

The reporting mandate arrives 15 months before the law's broader secure-by-design requirements.

Alongside vulnerabilities, the law also mandates reporting for "severe incidents." These are events that compromise the security of the product itself—such as a breach of a manufacturer's build environment or update servers that could allow malicious code to be pushed to end users. For these incidents, the final report is due within one month.[2][8]

The mandate explicitly targets "actively exploited vulnerabilities"—meaning there is reliable evidence that a malicious actor is using the flaw without permission. Routine security patches and vulnerabilities discovered and fixed internally before any exploitation occurs do not trigger the 24-hour reporting requirement.[1][2]

What remains unclear is exactly how ENISA will handle the incoming deluge of data. The Single Reporting Platform (SRP) is mandated to be operational by the September deadline, but large-scale load testing has not yet been publicly validated. There is thin evidence on how the platform will perform when a ubiquitous vulnerability—akin to Log4j—triggers simultaneous 24-hour reports from thousands of vendors.[2]

Despite the operational friction for manufacturers, this mandate is a watershed moment for enterprise security. By forcing a 24-hour disclosure window to national authorities, the CRA empowers CSIRTs to issue rapid ecosystem-wide warnings and coordinate defenses before an exploit can cascade through critical infrastructure.[7][8]

Continuous vulnerability monitoring of deployed code is now a legal necessity.

The deadline is already forcing a structural shift in software engineering. To meet the 24-hour window, companies are moving away from point-in-time security scans toward continuous, agentic monitoring systems that map threat intelligence directly to deployed SBOMs.[3][4]

The September 11 deadline is not a suggestion, and the grace period is evaporating. Manufacturers who wait for the broader 2027 enforcement date will find themselves legally exposed.[5]

The capability to detect, assess, and report an active exploit within a single day is no longer a best practice—it is the baseline cost of doing business in Europe. For consumers, it means the software they rely on is about to become significantly more transparent and secure.[8]

24 hours
Early warning deadline
72 hours
Detailed notification deadline
14 days
Final report deadline post-patch
€15 million
Maximum non-compliance penalty
15 months
Gap before full 2027 enforcement

Sources

Source coverage

8 outlets

3 viewpoints surfaced

Compliance & Legal Advisors 40%Security Tooling Vendors 35%EU Regulators 25%
  1. [1]European CommissionEU Regulators

    Frequently Asked Questions on Cyber Resilience Act Single Reporting Platform (CRA SRP)

    Read on European Commission
  2. [2]ElementCompliance & Legal Advisors

    Three Things Manufacturers Get Wrong About the CRA Reporting Obligations

    Read on Element
  3. [3]ArmorCodeSecurity Tooling Vendors

    Resolve EU Cyber Resilience Act (CRA) Compliance Challenges

    Read on ArmorCode
  4. [4]KeysightSecurity Tooling Vendors

    The EU Cyber Resilience Act (CRA) imposes a critical deadline on September 11, 2026

    Read on Keysight
  5. [5]CertivoCompliance & Legal Advisors

    EU CRA Vulnerability Reporting: The 24-Hour Rule and Retroactive Scope

    Read on Certivo
  6. [6]HeroDevsSecurity Tooling Vendors

    EU Cyber Resilience Act reporting obligations take effect September 11, 2026

    Read on HeroDevs
  7. [7]Northwave CybersecuritySecurity Tooling Vendors

    How to prepare for the first EU Cyber Resilience Act deadline

    Read on Northwave Cybersecurity
  8. [8]DLA PiperCompliance & Legal Advisors

    The CRA Reporting Framework: Operationalising the 24-Hour Window

    Read on DLA Piper

Comments

Stay informed

Every angle. Every day.

Get technology stories with full source coverage and perspective breakdowns delivered to your inbox.