EU Cyber Resilience Act's 24-Hour Breach Reporting Rule Is Live
Manufacturers of hardware and software for the EU market must now report actively exploited vulnerabilities and severe security incidents to regulators within 24 hours of awareness.
The EU’s Cyber Resilience Act (CRA) now requires manufacturers of products with digital elements (PDEs) to provide an "early warning" to regulators within 24 hours of becoming aware of an actively exploited vulnerability or a severe security incident. This is followed by a fuller notification within 72 hours. The rules apply to a wide range of hardware, software, and firmware products made available on the EU market, regardless of the manufacturer's location.
Counsel should note the severe penalties for non-compliance, which can reach up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher. These CRA obligations operate in parallel with, and do not replace, reporting duties under other key regulations like the GDPR and the NIS2 Directive, creating a complex, multi-track compliance challenge from a single event. The trigger for the 24-hour clock is when a company has a "reasonable degree of certainty" that an incident has occurred. Companies must immediately integrate the CRA’s distinct triggers and deadlines into their incident response plans, identify their specific national reporting authority, and train teams on the new awareness standard to avoid costly violations.