TheCyberExpress

EU’s 24-Hr Vulnerability Reporting Rules Take Effect Friday, A Year Before The Rest Of The Cyber Resilience Act


Manufacturers selling connected products in the European Union face a new legal duty starting Sept. 11. Report actively exploited vulnerabilities to authorities within 24 hours of confirming them. The obligation arrives 15 months ahead of the Cyber Resilience Act’s full application date of Dec. 11, 2027, making it the regulation’s first hard deadline.

The CRA covers products with digital elements placed on the EU market, a category broad enough to take in enterprise software, consumer IoT devices, industrial controllers and much of the component software beneath them.

Under Article 14, manufacturers must file an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident affecting product security, a fuller notification within 72 hours, and a final report within 14 days of a corrective measure becoming available — one month in the case of severe incidents.

Reports go through a Single Reporting Platform operated by ENISA. A manufacturer submits once to a designated national computer security incident response team, which then shares the notification with CSIRTs in other member states where the product is sold, with ENISA receiving it in parallel. The European Commission has said the platform will be operational by the September date and has been undergoing functional and security testing.

Where the Deadline Bites

The awareness standard is what will generate arguments. The trigger is a reasonable degree of certainty that a vulnerability is being exploited or that an incident has severely compromised product security — a judgment call that must be made in hours, often on partial telemetry, and one that manufacturers cannot defer by declining to investigate.

Two further wrinkles are drawing attention from compliance advisers. Reporting duties survive end of support, unlike most of the CRA’s other vulnerability-handling requirements, which means legacy product lines remain in scope. And importers or distributors that rebrand a product or substantially modify it inherit manufacturer obligations outright.

Penalties for breaching core manufacturer obligations reach €15 million or 2.5% of global annual turnover, whichever is higher.

Readiness Questions on the Cyber Resilience Act

Practitioners have raised two gaps. The reporting platform is scheduled to be ready by the deadline rather than in advance of it, leaving little room for manufacturers to rehearse submissions. And the harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so companies are building processes against a moving target. The CRA’s requirement that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027.

The effects reach past manufacturers. Enterprises that buy connected products will begin receiving vendor notifications on the vendor’s clock rather than their own, and will need a route from a supplier advisory into incident triage — plus a fast assessment of whether the same event triggers separate duties under NIS2 or DORA.

Friday’s start date has an immediate real-world test case. Adobe confirmed this week that a maximum-severity Magento flaw, CVE-2026-75650, has been exploited against merchants since Sept. 4. Had the same sequence begun a week later, the 24-hour clock would have applied.

Read: Attackers Exploit Unpatched Magento Zero-Day to Backdoor Online Stores



Source link