Helpnetsecurity EU Cyber Resilience Act Reporting Deadlines Now in Effect
Article Content
- •Manufacturers must report cybersecurity incidents within 24 hours under the CRA.
- •The Single Reporting Platform launched by ENISA streamlines incident reporting.
- •Non-compliance with reporting obligations can lead to significant financial penalties.
As of September 11, 2026, the EU Cyber Resilience Act (CRA) mandates that manufacturers of products with digital elements (PDEs) report actively exploited vulnerabilities and severe incidents within strict deadlines. An early warning must be submitted within 24 hours of awareness, followed by a fuller notification within 72 hours, and a final report within 14 days or one month, depending on the incident type. The Single Reporting Platform (SRP) developed by ENISA facilitates this reporting process, allowing manufacturers to submit notifications electronically to designated Computer Security Incident Response Teams (CSIRTs). This platform is crucial for ensuring timely communication of cybersecurity incidents across the EU market. Non-EU manufacturers are also subject to these obligations if their products are available in the EU. Failure to comply can result in penalties of up to EUR 15 million or 2.5% of global annual turnover. The CRA's implementation is part of broader EU efforts to enhance cybersecurity resilience.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track IDScan in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…