started · updated
EU Cyber Resilience Act mandates 24-hour security reporting
The European Union’s Cyber Resilience Act (CRA) has activated its mandatory reporting requirements for manufacturers of products with digital elements, including software, IoT devices, and crypto wallets. As of September 11, 2026, companies must adhere to a strict three-stage notification process for actively exploited vulnerabilities and severe security incidents.
Manufacturers are required to issue an early warning within 24 hours of discovery. This must be followed by a detailed notification within 72 hours. Final reports are due within 14 days for exploited vulnerabilities once a patch is available, or within one month for severe security incidents. These reports are submitted via a centralized EU platform managed by ENISA.
While the broader security-by-design requirements for products will not fully apply until December 2027, the immediate reporting obligations place significant operational pressure on businesses. Industry surveys, such as those by Bitkom, suggest that many companies remain unprepared for the technical and administrative demands of the regulation. Non-compliance carries heavy penalties, including fines of up to €15 million or 2.5% of global annual turnover.
Entities
BSI · Bitkom · Cyber Resilience Act · ENISA · European Union · European Union Agency for Cybersecurity · NIS2 Directive · NXP · PwC
Claims
What the coverage asserts, and how many sources carry each claim.
- [○ 1 SOURCE] Half of the surveyed companies lack a dedicated external interface for security reporting. www.silicon.de
- [○ 1 SOURCE] Only 3 percent of surveyed German industrial companies consider themselves fully compliant with the CRA. www.silicon.de
- [● 11 SOURCES] Manufacturers must provide an early warning within 24 hours of becoming aware of an issue. techformator.pl · borncity.com · bezprawnik.pl · zeitenvogel.de · www.techgear.gr · +6 more
- [● 3 SOURCES] The EU Cyber Resilience Act (CRA) entered into force on December 10, 2024. techformator.pl · borncity.com · www.silicon.de
- [● 11 SOURCES] A detailed report must be submitted within 72 hours of the initial notification. techformator.pl · borncity.com · bezprawnik.pl · zeitenvogel.de · www.techgear.gr · +6 more
- [● 12 SOURCES] Reporting obligations for actively exploited vulnerabilities and serious security incidents became active on September 11, 2026. techformator.pl · borncity.com · www.silicon.de · bezprawnik.pl · zeitenvogel.de · +7 more
- [● 7 SOURCES] For severe security incidents, a final report must be submitted within one month of the 72-hour notification. blockchainreporter.net · www.casadomo.com · www.enterprisesecuritytech.com · borncity.com · cryptoslate.com · +2 more
- [● 7 SOURCES] For exploited vulnerabilities, a final report is due within 14 days of a corrective or mitigating measure becoming available. blockchainreporter.net · www.casadomo.com · www.enterprisesecuritytech.com · borncity.com · cryptoslate.com · +2 more
- [○ 1 SOURCE] Non-compliance with the CRA can lead to administrative penalties of up to €15 million or 2.5% of worldwide annual turnover. www.cryptobreaking.com
- [● 3 SOURCES] The CRA applies to manufacturers of products with digital elements, including hardware and software crypto wallets. blockchainreporter.net · www.cryptobreaking.com · cryptoslate.com