< Back to all clusters
[TECHNOLOGY] · Germany, Greece, Italy, Japan, Norway · 16 sources

started · updated

EU Cyber Resilience Act mandates 24-hour security reporting

The European Union’s Cyber Resilience Act (CRA) has activated its mandatory reporting requirements for manufacturers of products with digital elements, including software, IoT devices, and crypto wallets. As of September 11, 2026, companies must adhere to a strict three-stage notification process for actively exploited vulnerabilities and severe security incidents.

Manufacturers are required to issue an early warning within 24 hours of discovery. This must be followed by a detailed notification within 72 hours. Final reports are due within 14 days for exploited vulnerabilities once a patch is available, or within one month for severe security incidents. These reports are submitted via a centralized EU platform managed by ENISA.

While the broader security-by-design requirements for products will not fully apply until December 2027, the immediate reporting obligations place significant operational pressure on businesses. Industry surveys, such as those by Bitkom, suggest that many companies remain unprepared for the technical and administrative demands of the regulation. Non-compliance carries heavy penalties, including fines of up to €15 million or 2.5% of global annual turnover.

Entities

BSI · Bitkom · Cyber Resilience Act · ENISA · European Union · European Union Agency for Cybersecurity · NIS2 Directive · NXP · PwC

Claims

What the coverage asserts, and how many sources carry each claim.

Sources

1 day ago
about 17 hours ago
about 19 hours ago