< Back to all clusters
[TECHNOLOGY] · EU · 19 sources

started · updated

EU Cyber Resilience Act reporting mandates take effect

On September 11, 2026, the European Union’s Cyber Resilience Act (CRA) entered its first operational phase, mandating strict reporting requirements for manufacturers of products with digital elements. This includes software, connected hardware, and IoT devices such as smart home equipment and industrial controllers.

Under Article 14, manufacturers must report actively exploited vulnerabilities or severe security incidents through ENISA’s Single Reporting Platform (SRP). The reporting timeline is highly compressed: an initial early warning must be issued within 24 hours of discovery, a detailed notification within 72 hours, and a final report within 14 days of a mitigation becoming available. For severe incidents, the final report is due within one month.

Non-compliance carries significant financial penalties, with fines reaching up to 15 million Euros or 2.5% of a company’s total global annual turnover. While these immediate reporting obligations are now in effect, the broader set of CRA requirements, including full compliance for CE marking, is scheduled for implementation by December 11, 2027.

Entities

Bitkom · ENISA · European Commission · European Union · European Union · European Union Agency for Cybersecurity · Genetec Inc. · Mathieu Chevalier · NORD DRIVESYSTEMS · NewTec

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

Fristgerecht zum heutigen Stichtag [www.deutscherpresseindex.de]