EU Cyber Resilience Act Reporting Rules Now Enforced
Article Content
- •Manufacturers must report cybersecurity incidents within strict deadlines.
- •The CRA aims to unify and strengthen cybersecurity regulations across the EU.
- •Broader obligations under the CRA will take effect by December 11, 2027.
As of September 11, 2026, manufacturers of connected hardware and software in the EU are required to report actively exploited vulnerabilities and serious security incidents under the Cyber Resilience Act (CRA). This legislation aims to enhance the cybersecurity of products with digital elements, responding to the increasing number of cyberattacks. Manufacturers must notify the European Union Agency for Cybersecurity (ENISA) and national Computer Security Incident Response Teams (CSIRTs) through a new Single Reporting Platform. Initial warnings must be submitted within 24 hours of awareness, followed by detailed notifications within 72 hours. The CRA introduces significant compliance obligations, transforming voluntary practices into enforceable duties. The broader cybersecurity requirements of the CRA will become fully applicable on December 11, 2027. This change marks a shift towards a more unified regulatory framework across EU member states, addressing previously fragmented cybersecurity requirements.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…