started · updated
EU Cyber Resilience Act mandates vulnerability reporting deadlines
The European Union’s Cyber Resilience Act (CRA) is introducing mandatory cybersecurity requirements for products with digital elements. While the full regulation becomes applicable on 11 December 2027, a critical deadline for reporting actively exploited vulnerabilities and severe incidents is set for 11 September 2026.
Under these rules, manufacturers and machine builders must adhere to a strict, three-tiered reporting timeline involving the European Union Agency for Cybersecurity (ENISA) and relevant incident response teams. Required actions must be taken within 24 hours, 72 hours, and 14 days of an incident occurring.
The scope of the CRA covers hardware and software products that involve direct or indirect logical or physical data connections to a device or network. This includes industrial components such as industrial PCs, programmable logic controllers (PLCs), IoT gateways, and various firmware or operating systems. Non-compliance could result in significant penalties, reaching up to €15 million or 2.5% of a company’s global annual turnover.
Entities
European Union · European Union Agency for Cybersecurity · Mitsubishi Electric