Skip to main content

Cyber Resilience Act

EU Cyber Resilience Act Triggers First Reporting Duties on Sept 11, 2026

Image
EU Cyber Resilience Act Triggers First Reporting Duties on Sept 11, 2026

Cologne – – September 15, 2026 -- Manufacturers of connected devices, industrial controls, routers and software products face their first binding reporting deadline under the EU Cyber Resilience Act (CRA) on September 11, 2026, when mandatory notification of actively exploited vulnerabilities and severe security incidents begins via a centralized EU reporting platform.

Manufacturers must report exploited flaws within 24 hours

Under the CRA, manufacturers must submit an early warning within 24 hours of learning that a vulnerability in their own product is being actively exploited, followed by a supplementary report within 72 hours. A final report is due no later than 14 days after a remediation or risk-mitigation measure is implemented.

Severe security incidents affecting product security carry the same 24-hour and 72-hour notification windows, with a final report required within one month of the incident report.