Theregister iconTheregisterSep 11, 2026 ~7 min source read

EU Cyber Resilience Act starts 24-hour clock for exploited vulnerabilities

From 11 September 2026 manufacturers selling products with digital elements in the EU must file an initial report to ENISA within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident, with follow-ups required at 72 hours and final reports later.

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

Share this story

Send the public story page.

Useful takeaways from this story.

Manufacturers must submit an early warning via ENISA's Single Reporting Platform within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident.

Core CRA duties carry the highest fines: failures to comply with reporting obligations can trigger penalties up to €15 million or 2.5% of annual turnover.

# What changed on 11 September 2026

Act (CRA) began requiring manufacturers who place products with digital elements on the EU market to report actively exploited vulnerabilities and severe security incidents on tight timelines. The duty applies regardless of where the manufacturer is based, subject to the regulation's exemptions.

# The reporting timeline

  • Initial report: within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident.
  • Follow-up: a more detailed notification within 72 hours.

# Practical effects for manufacturers

Manufacturers can no longer delay mapping affected products after a vulnerability appears. The CRA requires a maintained, accurate view of a product's components and related products so manufacturers can identify what to report within the 24- and 72-hour windows. The act anticipates that software bills of materials (SBOMs) and continued traceability will be essential when further CRA provisions take effect.

Darren Anstee, CTO for security at Netscout, said: "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt." He added that faster sharing helps organisations put defences and mitigating controls in place when risk is heightened.

Eran Kinsbruner, vice president of product marketing at Checkmarx, said: "Secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list." He noted that modern applications combine proprietary code, open-source packages, third-party components and AI models and services, all of which need to be understood.

# User notifications and accountability

Manufacturers must inform affected users where appropriate about actively exploited vulnerabilities or severe incidents, and users must be told about available corrections or mitigations without undue delay. The CRA classifies these reporting duties as core responsibilities. Noncompliance can trigger the regulation's top-tier fines: up to €15 million or 2.5% of annual turnover, whichever is higher.

# Where this fits in the wider CRA rollout

Most remaining CRA provisions become applicable on 11 December 2027. At that point manufacturers must demonstrate security by design and default, which includes removing default passwords, delivering security updates as a requirement, and completing applicable conformity assessments before placing products on the EU market and affixing a CE mark. SBOMs and ongoing component traceability are expected to be mandatory parts of compliance.

# What manufacturers should do now

  • Ensure incident response and vulnerability-handling processes can produce an initial report within 24 hours and a 72-hour follow-up.
  • Maintain current inventories or SBOM-like records and update them through a product's lifecycle so affected components and dependencies can be identified quickly.
  • Identify the coordinating CSIRT under the CRA and register with ENISA's Single Reporting Platform.
  • Prepare user-notification procedures that communicate corrections and mitigations without undue delay.

# Bottom line

The CRA's reporting clock shifts urgency into manufacturers' day-to-day operations: rapid internal discovery and prepared, traceable inventories of software and components are now prerequisites to meet the new reporting deadlines.

More context around this story.

ЕС вводит правило 24 часов для сообщения о киберугрозах
Runet iconRunetAug 30, 2026

ЕС вводит правило 24 часов для сообщения о киберугрозах

В Евросоюзе с 11 сентября начнёт действовать требование Cyber Resilience Act, обязывающее производителей цифровых продуктов сообщать об активно эксплуатируемых уязвимостях и инцидентах. На первичное уведомление отводится 24 часа с момента обнаружения проблемы, полная информация должна быть предоставлена через 72 часа,

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app