Skip to content
EU Cyber Resilience Act Reporting Rules Now Enforced

EU Cyber Resilience Act Reporting Rules Now Enforced

First seen 22 Sep 2026, 08:53 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 09:53 UTC
  • Manufacturers must report cybersecurity incidents within strict deadlines.
  • The CRA aims to unify and strengthen cybersecurity regulations across the EU.
  • Broader obligations under the CRA will take effect by December 11, 2027.

As of September 11, 2026, manufacturers of connected hardware and software in the EU are required to report actively exploited vulnerabilities and serious security incidents under the Cyber Resilience Act (CRA). This legislation aims to enhance the cybersecurity of products with digital elements, responding to the increasing number of cyberattacks. Manufacturers must notify the European Union Agency for Cybersecurity (ENISA) and national Computer Security Incident Response Teams (CSIRTs) through a new Single Reporting Platform. Initial warnings must be submitted within 24 hours of awareness, followed by detailed notifications within 72 hours. The CRA introduces significant compliance obligations, transforming voluntary practices into enforceable duties. The broader cybersecurity requirements of the CRA will become fully applicable on December 11, 2027. This change marks a shift towards a more unified regulatory framework across EU member states, addressing previously fragmented cybersecurity requirements.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2024-10-23
EU Cyber Resilience Act adopted
The EU adopted the CRA to enhance cybersecurity for products with digital elements.
Mondaq
2026-09-11
CRA reporting requirements enforced
Manufacturers must report vulnerabilities and incidents via ENISA's Single Reporting Platform.
Linkedin
2026-09-22
Key reporting obligations discussed
Manufacturers are urged to prepare for compliance with the CRA's reporting obligations.
Mondaq

More articles in this cluster (3)