The EU's 24-hour clock starts on 11 September: Cyber Resilience Act reporting goes live
On 11 September 2026 the EU Cyber Resilience Act stops being a 2027 problem. From that date, any manufacturer placing a product with digital elements on the EU market — software, firmware, connected hardware — must report actively exploited vulnerabilities and severe incidents on a fixed clock: an early warning within 24 hours of becoming aware, a full notification within 72 hours, and a final report within 14 days of a fix being available (one month for severe incidents). Reports go once through ENISA's new CRA Single Reporting Platform, which routes them to the CSIRT where the manufacturer is established and to ENISA simultaneously, and onward to every other CSIRT where the product is sold. The Commission says the platform will be live on the day the obligation bites; functional and security testing is under way. The rest of the CRA — secure-by-design duties, CE marking, conformity assessment — follows on 11 December 2027, and the Commission published practical implementation guidance in July. The practical point for engineering teams is that 24 hours is an operational deadline, not a legal one: it presumes you already know what you ship, which components are in it, and who decides that a vulnerability is being exploited in the wild. If your SBOM, exploit-triage path and named reporting owner are not in place before Friday, the deadline will find them for you.
This is a summary by our content curator. Read the original at the European Commission: https://digital-strategy.ec.europa.eu/en/policies/cra-reporting.