AI

EU Cyber Resilience Act Reporting Rules Are Now Live — What the 24-Hour Deadline Means

By Nino Ray Yeh · September 14, 2026 · 6:53 pm AEST · 5 min read
EU Cyber Resilience Act reporting rules are now in force, giving manufacturers 24 hours to flag actively exploited vulnerabilities and severe cyber incidents.

Europe has just changed the rules for how technology companies respond when their products are being actively exploited.

From September 11, manufacturers selling connected hardware and software in the European Union are required to report certain serious cybersecurity problems within hours of discovering them — not days or weeks later.

The new requirements come from the EU Cyber Resilience Act, and they apply to a remarkably broad range of technology: software, apps, smart-home devices, wearables, connected security products and other products containing digital elements.

For technology companies, the important number is now 24 hours.

When a manufacturer becomes aware of an actively exploited vulnerability or a severe security incident affecting one of its products, it must submit an early warning within that window.

A more detailed notification follows within 72 hours.

That may sound like another compliance deadline buried inside European regulation. It isn’t.

The rule changes the economics of sitting on a security problem.

A vulnerability can no longer quietly sit in an internal ticket

Security teams have traditionally faced an uncomfortable calculation when a vulnerability appears.

How serious is it? Is someone actually exploiting it? Can the company reproduce it? Does it need a patch immediately? Should customers be told? Does disclosure itself create additional risk?

The Cyber Resilience Act doesn’t eliminate those questions, but it puts a clock next to some of them.

For an actively exploited vulnerability, manufacturers must issue an initial warning within 24 hours of becoming aware of it. The fuller notification is due within 72 hours.

Once a corrective or mitigating measure becomes available, a final vulnerability report must follow no later than 14 days later.

Severe security incidents have their own final-report deadline, generally within one month of the 72-hour notification.

That is a very different environment from one where a security flaw might be discussed internally for weeks before regulators know it exists.

ENISA has built a new reporting system for it

The European Union Agency for Cybersecurity, better known as ENISA, has launched a Single Reporting Platform specifically for the new regime.

Instead of manufacturers separately contacting authorities across multiple EU countries, the system is designed around a report-once approach.

The manufacturer submits the notification through the platform to the appropriate national computer-security incident response team, with ENISA also involved in the process. Relevant information can then be distributed to other authorities where necessary.

It sounds procedural, but the centralised platform is an important part of making the Cyber Resilience Act workable.

A connected device sold across Europe can potentially expose customers in dozens of countries. Coordinating the response country by country would quickly become its own incident-management problem.

The rules reach far beyond traditional cybersecurity companies

This is where the Cyber Resilience Act becomes particularly interesting.

It isn’t simply aimed at antivirus developers, cloud providers or companies selling enterprise security products.

The Commission describes the rules as applying to products with digital elements.

Think connected door locks.

Smartwatches.

Apps.

Computer software.

Internet-connected hardware.

Consumer gadgets that receive software updates.

For companies that have historically thought of themselves primarily as hardware manufacturers, cybersecurity is becoming part of the product lifecycle rather than an issue handed to an IT department after something goes wrong.

A smart appliance with vulnerable software is still a vulnerable computing device, even if consumers don’t normally think of it that way.

Products already on sale aren’t automatically outside the reporting rules

There is another detail companies shouldn’t overlook.

The reporting obligations apply to products with digital elements made available in the EU, including products already on the market.

That matters because the Cyber Resilience Act’s wider requirements don’t fully apply until December 11, 2027.

Manufacturers therefore shouldn’t assume they can ignore the current reporting requirements until the rest of the legislation reaches full application.

The reporting phase has already started.

Open-source software stewards have a different timetable, with their relevant reporting obligations beginning in December 2027.

What this could mean for consumers

For ordinary buyers, none of this means vulnerabilities suddenly disappear.

Software will still have bugs. Connected devices will still be attacked. Security researchers will continue finding flaws manufacturers missed.

What changes is the expectation surrounding the response.

The EU wants serious, actively exploited vulnerabilities to move quickly from internal discovery to coordinated action.

That should give authorities earlier visibility into attacks spreading across widely used products and increase pressure on manufacturers to maintain security processes long after a device first reaches store shelves.

It also makes long-term software support increasingly difficult to treat as a marketing extra.

If a company intends to sell a connected device into one of the world’s largest consumer markets, being able to identify, investigate, report and remediate vulnerabilities is becoming part of the cost of doing business.

The bigger story is accountability

Technology regulation often arrives years after the behaviour it is trying to control.

The Cyber Resilience Act is different in one important respect: it is addressing a problem that is becoming more urgent as everyday objects become computers.

Cars contain software.

Doorbells connect to servers.

Watches hold personal information.

Home security systems are remotely accessible.

Even relatively simple consumer electronics may now depend on cloud accounts, mobile apps and firmware updates.

Every additional connection creates another potential route for attack.

Europe’s answer is increasingly clear: if companies put connected products into people’s homes, workplaces and pockets, cybersecurity can’t end when the product leaves the factory.

And from September 11, when a serious vulnerability is already being exploited, the clock starts ticking.

Share this story

Topics

More From The Tech Boom

View all

Share with