EU's Cyber Resilience Act Imposes 24-Hour Reporting Deadline
Manufacturers of connected products sold in the EU must now report actively exploited vulnerabilities and severe security incidents within 24 hours of awareness, with potential fines of up to €15 million or 2.5% of global turnover.
The EU's Cyber Resilience Act (CRA) reporting regime took effect on September 11, 2026, imposing stringent new obligations on manufacturers of connected products. The act covers a vast range of "products with digital elements" (PDEs), including software, hardware, and IoT devices, that are made available on the EU market. The key change is an exceptionally fast reporting timeline: manufacturers must provide an "early warning" to the EU's cybersecurity agency (ENISA) and national authorities within 24 hours of becoming aware of either an actively exploited vulnerability or a severe security incident impacting their product. A more detailed notification is required within 72 hours.
These rules apply extraterritorially, affecting any manufacturer worldwide selling into the EU. The potential penalties are significant, with fines of up to €15 million or 2.5% of total global turnover, whichever is greater. These CRA duties are cumulative and do not replace separate reporting obligations under GDPR or the NIS2 Directive, adding another layer of complexity to incident response. Companies should urgently update their incident response playbooks to incorporate the CRA's triggers and tight deadlines, identify their coordinating EU cybersecurity authority, and train relevant teams on the new requirements.