EU Cyber Resilience Act Reporting Obligations Now in Effect
Article Content
- •Manufacturers must report vulnerabilities and incidents affecting digital products.
- •Early warning notifications are required within 24 hours of awareness.
- •NCSC has published guidelines to assist compliance with the new reporting obligations.
As of September 11, 2026, manufacturers in the EU must report actively exploited vulnerabilities and severe incidents affecting digital products under the Cyber Resilience Act (CRA). This regulation, which aims to enhance cybersecurity for products with digital elements, was established in December 2024 and is being phased in until December 2027. The new obligations require manufacturers to provide early warning notifications within 24 hours of awareness of a vulnerability or incident, followed by detailed vulnerability notifications within 72 hours. The National Cyber Security Centre (NCSC) in Ireland has published guidelines to assist manufacturers in complying with these requirements. Justice Minister Jim O’Callaghan emphasized the Act's role in improving the security of citizens and businesses against cyber threats. The guidelines include information on reporting thresholds and procedures, aiming to facilitate timely compliance.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…