EU Cyber Resilience Act Enforces New Reporting Requirements for Digital Products
Article Content
- •New reporting requirements for digital products in the EU effective September 11, 2026.
- •Manufacturers must report vulnerabilities within 24 hours and provide detailed notifications within 72 hours.
- •The CRA's obligations apply to products already on the market, not just new releases.
Effective September 11, 2026, the EU Cyber Resilience Act mandates manufacturers of products with digital elements to report vulnerabilities and incidents. This new framework shifts regulatory focus from corporate networks to the cybersecurity of hardware and software products in the EU market. Manufacturers must notify authorities within 24 hours of discovering actively exploited vulnerabilities or severe incidents. Detailed reports are required within 72 hours, with final reports due within one month or 14 days after a fix is available. This obligation applies to products already on the market, emphasizing the need for rapid preliminary reporting. Most other CRA obligations will not take effect until December 11, 2027.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…