[REVISION HISTORY]
EU Cyber Resilience Act reporting obligations take effect
Updated 8 times since CLSTR started tracking revisions of this situation.
What changed
2026-09-11 15:11 UTC → 2026-09-15 10:38 UTC ·
added
removed
The EU Cyber Resilience Act (CRA) has officially entered its first mandatory phase as of on 11 September 2026. This initial stage enforces Article 14, requiring manufacturers of products with digital elements to elements—including software, connected hardware, and IoT devices like industrial controllers and smart home equipment—to report actively exploited vulnerabilities and severe security incidents. Under these active regulations, companies must utilize a centralized Single Reporting Platform operated by ENISA. The mandatory three-stage procedure requires an initial early warning within 24 hours of discovery, a detailed notification within 72 hours, and a final comprehensive report within 14 days for vulnerabilities or one month for severe incidents. Experts clarify that the 24-hour requirement serves as an ‘escalation or alarm bell’ rather than a completed investigation. These immediate reporting duties apply to both new and existing products currently on the market, covering software developers, hardware manufacturers, and importers or distributors who rebrand products. While broader CRA requirements, such as CE marking, remain set for 11 December 2027, the current reporting obligations are already in effect. Non-compliance carries significant financial risks, with potential fines of up to 15 million euros or 2.5 percent of a company’s total worldwide annual turnover. Providing false, incomplete, or misleading information can result in additional fines of up to 5 million euros. Industry experts have highlighted potential implementation challenges, including the technical difficulty of distinguishing between a mere vulnerability and an active exploitation, as well as the necessity for robust Software Bills of Materials (SBOM) to manage risk effectively.
Versions
- 2026-09-15 10:38 UTC EU Cyber Resilience Act reporting obligations take effect
- 2026-09-11 15:11 UTC EU Cyber Resilience Act reporting obligations take effect
- 2026-09-10 10:11 UTC EU Cyber Resilience Act compliance and reporting
- 2026-09-01 08:25 UTC EU Cyber Resilience Act compliance and reporting
- 2026-08-18 06:06 UTC EU Cyber Resilience Act compliance and reporting
- 2026-08-17 23:35 UTC EU Cyber Resilience Act compliance and reporting
- 2026-08-12 09:30 UTC EU Cyber Resilience Act compliance and reporting
- 2026-08-05 05:53 UTC EU Cyber Resilience Act compliance
- 2026-07-28 09:02 UTC EU Cyber Resilience Act compliance
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.