EU's Cyber Resilience Act vulnerability reporting rules take effect today

The first enforceable phase of the European Union's Cyber Resilience Act took effect September 11, imposing mandatory vulnerability and incident reporting obligations on manufacturers of connected software and hardware products sold in the EU — including legacy products already on the market before the CRA applies in full.
This is a meaningfully different kind of cybersecurity news than a breach disclosure or an actively exploited flaw: it's the point at which vulnerability reporting stops being a best practice and becomes a hard legal requirement backed by regulatory penalties across the entire EU market.
What manufacturers must now do
Under the new rules, manufacturers must notify authorities of actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements on a strict timeline: an early warning within 24 hours of becoming aware of the issue, a full notification within 72 hours, and a final report no later than 14 days after a corrective measure becomes available for actively exploited vulnerabilities (within a month for severe incidents).
Reporting happens through the CRA's new Single Reporting Platform (SRP), run by ENISA, the EU's cybersecurity agency. The platform lets manufacturers file one report that reaches all relevant national authorities, rather than requiring separate notifications to each EU member state where their products are sold — a structural fix to what had been a genuinely fragmented compliance burden.
Why this matters beyond the EU
The CRA applies to any manufacturer selling connected products into the EU market, regardless of where the company is headquartered — the same extraterritorial reach that made GDPR a global compliance reference point rather than a purely European one. A US or Asian hardware or software vendor with EU customers now faces the same 24-hour disclosure clock as an EU-based manufacturer.
That timeline is aggressive by industry standards. Many companies' internal vulnerability response processes were not built around a 24-hour external disclosure requirement, and legal and cybersecurity advisory firms have been urging clients for months to have CRA reporting playbooks — including pre-approved internal escalation paths — ready before this date, rather than improvising them under a live deadline.
What comes next
This is only the first phase. The CRA's broader requirements — including mandatory security-by-design standards, CE marking for products with digital elements, and a longer transition period for full conformity assessment — phase in over the following two years. September 11's reporting obligations are the first point at which the regulation has real, immediate teeth, and the first real-world test of whether the Single Reporting Platform can handle the volume of disclosures a mandatory, EU-wide requirement is likely to generate.
Source: European Commission: Cyber Resilience Act — Reporting Obligations
Originally reported by European Commission. Read the original article for additional details.
View original source