EU Cyber Resilience Act enforces strict 24-hour vulnerability reporting for tech manufacturers.

Noncompliance can carry fines of up to €15 million or 2.5% of a company’s global annual turnover, whichever is higher.
The CRA’s broader compliance regime will eventually require secure-by-design engineering, CE marking, conformity assessments and formal Software Bill of Materials production; those requirements do not apply until Dec. 11, 2027.
Most products covered by the CRA are self-assessed, leaving manufacturers responsible for maintaining evidence that a vulnerability affects a shipped product and is reachable or executable; inability to produce that evidence could jeopardize a company’s ability to sell in the EU.
Some products considered particularly important to cybersecurity may require assessment by an independent notified body before they can be placed on the EU market, while national market-surveillance authorities will enforce the rules.
The first 24-hour filing is designed as an early alert rather than a complete technical account, meaning manufacturers are not expected to wait for a fully developed investigation before notifying authorities; this requires a documented escalation route linking security, incident response, legal, compliance and executive teams.
The European Union's Cyber Resilience Act entered enforcement on September 11, 2026, forcing manufacturers to report actively exploited vulnerabilities within 24 hours. WebProNews reported that companies selling hardware and software with digital elements in the EU now face tight deadlines: an early alert within 24 hours, a fuller notification within 72 hours, and a final report within 14 days or one month depending on the issue type. Noncompliance carries fines up to €15 million or 2.5% of global annual turnover, whichever is higher.
The 24-hour deadline is designed as a quick alert, not a complete investigation. JDSupra explained that manufacturers are not expected to wait for full technical analysis before notifying authorities. This requires manufacturers to quickly determine whether a flaw affects a shipped product and is actually exploitable — a challenge that demands firmware visibility, software inventories, and documented escalation procedures linking security, incident response, legal, compliance and executive teams.
Starting September 11, 2026, manufacturers must file a preliminary notice within 24 hours of learning about a qualifying vulnerability or severe security incident. Industrial Cyber reported that this first filing is intentionally lightweight — an early warning meant to alert regulators quickly rather than provide complete technical details. Companies must then submit a fuller notification within 72 hours and a comprehensive final report within 14 days for exploited vulnerabilities or one month for severe incidents.
All reports flow through the CRA Single Reporting Platform, which routes them to national cybersecurity response teams and ENISA, the EU's cybersecurity agency. The early-alert design removes the pressure to wait for a fully developed investigation before notifying authorities, but it requires manufacturers to have escalation procedures in place linking security, legal, and executive teams so they can act fast.
Most CRA-covered products are self-assessed, meaning manufacturers bear the burden of proving a vulnerability affects a shipped product and is reachable or executable. JDSupra noted that inability to produce this evidence could jeopardize a company's ability to sell in the EU. This requirement puts pressure on companies to maintain detailed software inventories and firmware visibility — not just patch management, but proof that a flaw is actually exploitable in deployed products.
Finite State highlighted firmware visibility as a critical challenge as the Act takes effect. Connected device manufacturers must quickly map which products contain a vulnerable component and whether it can actually be reached in real-world use. This means companies need automated tools and documented procedures to trace a flaw from code to shipped product in hours, not weeks.
The reporting obligations that began September 11 are just the first phase. Goodwin explained that the CRA's full compliance regime takes effect December 11, 2027, introducing secure-by-design engineering, CE marking, conformity assessments, and mandatory Software Bills of Materials. Some products deemed particularly critical to cybersecurity may require independent third-party assessment before they can enter the EU market.
National market-surveillance authorities will enforce the rules across member states. For now, manufacturers must focus on the September 11 reporting deadlines while preparing for 2027's broader design and documentation requirements. Companies lacking firmware visibility or formal escalation procedures face immediate risk of missed 24-hour deadlines and potential fines.
Publishers
13
Articles
12
Reach
25