Goodwin Procter·CYBERSECURITY

EU Cyber Resilience Act Sets Tight Deadlines for Incident Reporting

Manufacturers of hardware and software sold in the EU face a 24-hour deadline to report actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act, with key obligations taking effect on September 11, 2026.

The EU's Cyber Resilience Act (CRA) will impose significant new cybersecurity obligations, with reporting duties for manufacturers taking effect September 11, 2026. The rules apply to nearly all hardware and software with a data connection ("products with digital elements") made available on the EU market. This creates a harmonized, stringent framework across the EU, requiring manufacturers to report actively exploited vulnerabilities and severe security incidents to national authorities via a central EU platform. An initial notification is required within 24 hours of awareness, followed by a more detailed report within 72 hours. Penalties for non-compliance are severe, reaching up to €15 million or 2.5% of global annual turnover. The obligations also extend to vulnerabilities in third-party components. Counsel should advise clients to immediately identify covered products and establish internal procedures for rapid incident detection and reporting to meet the tight timelines. The CRA's broader product security and conformity requirements will apply from December 11, 2027.

cyber-resilience-acteucybersecurityincident-reportingproduct-liabilityregulatory-complianceenisa
Read the original firm alert → Saturday, September 12, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.