Skip to main content

EU Cyber Resilience Act Triggers First Reporting Duties on Sept 11, 2026

Image
EU Cyber Resilience Act Triggers First Reporting Duties on Sept 11, 2026

Cologne – – September 15, 2026 -- Manufacturers of connected devices, industrial controls, routers and software products face their first binding reporting deadline under the EU Cyber Resilience Act (CRA) on September 11, 2026, when mandatory notification of actively exploited vulnerabilities and severe security incidents begins via a centralized EU reporting platform.

Manufacturers must report exploited flaws within 24 hours

Under the CRA, manufacturers must submit an early warning within 24 hours of learning that a vulnerability in their own product is being actively exploited, followed by a supplementary report within 72 hours. A final report is due no later than 14 days after a remediation or risk-mitigation measure is implemented.

Severe security incidents affecting product security carry the same 24-hour and 72-hour notification windows, with a final report required within one month of the incident report.

Not every CVE entry triggers a mandatory CRA report

A listing in the Common Vulnerabilities and Exposures (CVE) database or a penetration test finding alone does not create a reporting obligation, according to Stefan Eigler, cybersecurity expert and Segment Manager for Mastering Risk & Compliance at TÜV Rheinland. The decisive factor is whether active exploitation of a vulnerability is confirmed.

Eigler calls the September 2026 deadline "the first concrete stress test" of corporate CRA readiness.

Companies wrongly assume duties start only in December 2027

Many firms currently operate under two false assumptions, Eigler said: that reporting obligations begin only in December 2027, and that only manufacturers of "important" or "critical" products are covered. In fact, the reporting duty applies broadly to manufacturers of all products with digital elements falling within CRA scope, including products already placed on the market before December 11, 2027.

CRA applies to non-EU manufacturers selling into the bloc

The Cyber Resilience Act entered into force on December 10, 2024, aiming to strengthen cybersecurity across the full lifecycle of products with digital elements. It covers hardware and software connected directly or indirectly to a device or network, including Industry 4.0 components, embedded systems and network equipment. Manufacturers headquartered outside the EU must comply if they place covered products on the EU market.

TÜV Rheinland advises companies to establish clear responsibilities, documented escalation paths and rapid access to technical incident data, alongside processes for promptly informing affected users of required corrective or mitigation actions.

Published by
fairsonline_team
Company
News Type