Seyfarth Shaw·CYBERSECURITY

EU Cyber Resilience Act's First Reporting Deadline Arrives

Manufacturers of hardware and software sold in the EU must now report actively exploited vulnerabilities and severe incidents to ENISA, with initial notifications due within 24 hours of awareness.

The first major compliance deadline under the EU's Cyber Resilience Act (CRA) is now in effect. As of September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents that impact their "products with digital elements" (PDEs). The CRA's scope is extensive, covering most software and hardware products placed on the EU market, irrespective of the manufacturer's location, size, or sector.

This creates an immediate and critical compliance burden for global businesses. The reporting timelines are extremely aggressive: an 'early warning' notification must be submitted to the EU's cybersecurity agency, ENISA, via its Single Reporting Platform within 24 hours of awareness. A more detailed notification must follow within 72 hours. These obligations are distinct from and apply more broadly than those under the existing NIS2 Directive.

Companies whose products are sold in the EU must ensure their incident response plans and operational workflows are equipped to meet these rapid reporting requirements. While the CRA’s full suite of cybersecurity design and development requirements does not take effect until December 2027, this initial reporting duty demands immediate readiness to avoid significant penalties.

eucybersecuritycyber-resilience-actincident-responsereporting-obligationsenisa
Read the original firm alert → Friday, September 18, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.