preloader

· · compliance eu cyber-resilience-act digital-security regulation europe vulnerability-management devops enisa

The EU Cyber Resilience Act’s Reporting Clock Started Today. Most Manufacturers Are Not Ready

Source: European Commission

Regulations with a hard start date are usually paired with a tool that has been live and tested for months before anyone has to use it under pressure. The EU Cyber Resilience Act’s incident and vulnerability reporting duty broke that pattern. Both the obligation and the platform meant to receive those reports arrived on the same day: today.

What actually changed today

Article 14 of the Cyber Resilience Act is now in force. Any manufacturer placing a product with digital elements on the EU market, hardware or software, consumer or enterprise, must now report to ENISA’s Single Reporting Platform whenever it becomes aware of a vulnerability being actively exploited or a severe incident affecting one of its products. The clock does not wait for convenience:

  • 24 hours for an initial early warning once you become aware of active exploitation or a severe incident
  • 72 hours for a fuller notification, including a preliminary severity assessment
  • 14 days after a fix ships for the final vulnerability report
  • One month for the final incident report on severe incidents

Reports route through the national competent authority in whichever member state applies, in parallel with ENISA’s central platform. The scope reaches further than most product teams expect: operating systems, browsers, password managers, VPN clients, firewalls, network equipment, industrial controllers, and software-as-a-service offerings that ship even a small locally installed component.

The platform launched on the deadline, not before it

The detail that makes today different from a routine compliance start date is that ENISA’s Single Reporting Platform was scheduled to go live on 11 September 2026, the exact date the reporting obligation takes effect. Functional and security testing were reportedly still under way in the platform’s final days, and its public URL was not published in advance the way most government portals are. Manufacturers who wanted to run a dry submission before their first real report had no platform to test against. That is not a footnote; it is the practical risk every affected company is carrying into today.

Compare that to how most regulatory deadlines work. GDPR’s breach notification duty had a functioning national process to plug into from day one. The CRA’s equivalent tool for cross-border reporting arrived at the same moment the countdown for a first breach or exploited CVE started running.

Why this catches more companies than they expect

Two groups consistently underestimate their own exposure. First, companies that treat “manufacturer” as meaning hardware vendors, when the CRA’s definition also catches software publishers and any SaaS product with a client-side component. Second, companies that integrate third-party components, open source or commercial, into a product they sell: they are on the hook for vulnerabilities in those components too, not just code they wrote themselves. If a dependency you ship is exploited in the wild, the 24-hour clock starts whether or not you had visibility into that dependency’s own disclosure process.

The penalties back up the urgency. Failing to meet the reporting obligations carries fines of up to €15 million or 2.5% of global annual turnover, whichever is higher, and providing incomplete or misleading reports carries its own separate fine tier.

What to do this week

If your product portfolio touches the EU market and you have not yet confirmed which national competent authority receives your reports, that is the first gap to close, not the last. Second, make sure whoever owns vulnerability triage internally knows the 24-hour window starts from awareness, not from confirmation or from a fix being ready, which means a Friday evening disclosure from a researcher becomes a Saturday deadline. Third, treat the platform’s late arrival as a reason to test your submission process at the first low-severity opportunity rather than waiting for a real incident to be your first attempt.

If you need help mapping your product portfolio against CRA scope, building a vulnerability response process that can hit a 24-hour window under pressure, or figuring out which of your dependencies now carry reporting obligations you did not know you had, contact Excello Digital. We help European software and hardware teams turn regulatory deadlines like this one into a process that actually works the first time it is tested for real.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!