EU Agencies Demand Timely Cybersecurity Reporting from Manufacturers

by priyanka.patel tech editor
EU Agencies Demand Timely Cybersecurity Reporting from Manufacturers

The EU’s Cyber Resilience Act (CRA) mandates new cybersecurity reporting obligations for manufacturers, effective September 11, 2026, requiring timely disclosure of actively exploited vulnerabilities and severe incidents to national CSIRTs and ENISA.

Starting September 11, 2026, companies must notify national Computer Security Incident Response Teams (CSIRTs) and the European Union Agency for Cybersecurity (ENISA) of actively exploited vulnerabilities and severe security incidents within 24 hours, with detailed follow-ups due within 72 hours and 14 days for vulnerabilities.

Key Deadlines and Reporting Timelines

The CRA’s reporting obligations, effective September 11, 2026, apply to all products with digital elements placed on the EU market, including those manufactured before December 11, 2027, if they remain in use. Manufacturers must report actively exploited vulnerabilities—security flaws actively used by threat actors—and severe incidents, defined as events that compromise data integrity, confidentiality, or availability, or enable malicious code execution. TechTarget highlights that the 24-hour rule requires an initial notification upon awareness, followed by a detailed assessment within 72 hours and a final report within 14 days for vulnerabilities or a month for severe incidents.

The European Commission emphasized that the reporting framework demands progressive updates as investigations advance, with manufacturers required to provide more detailed information as their understanding of the incident evolves. TechTarget quotes cybersecurity advisor Sai Honig, noting, It doesn’t matter if the product shipped in 2019. If it’s still in use and contains an actively exploited vulnerability, it must be reported. Noncompliance risks fines of up to €15 million or 2.5% of global annual turnover, whichever is higher.

The Role of the Single Reporting Platform

To streamline compliance, the EU’s ENISA launched the Cyber Resilience Act (CRA) Single Reporting Platform (SRP) on September 11, 2026, enabling manufacturers and open-source software stewards to submit reports once, with automated dissemination to relevant CSIRTs across member states.

ENISA’s Executive Director, Juhan Lepassaar, underscored the SRP’s role in building a more resilient Digital Single Market, citing vulnerabilities in digital products as a primary threat to critical sectors like healthcare and energy. Manufacturers must submit notifications through the SRP, which then routes information to ENISA and the relevant national CSIRT. ENISA also noted that open-source software stewards face similar obligations, though their full compliance requirements will take effect in 2027.

Implications for Manufacturers and Open-Source Stewards

The CRA’s reporting mandates represent a structural shift in cybersecurity accountability, placing responsibility on manufacturers to ensure products remain secure throughout their lifecycle.

By requiring proactive reporting, the CRA seeks to align incentives, ensuring manufacturers address vulnerabilities even in older products still in use. Goodwinlaw added that the law’s broader obligations—such as cybersecurity risk assessments and conformity certifications—will apply to products launched after December 11, 2027, or those undergoing substantial modification.

For open-source software stewards, the CRA introduces lighter obligations compared to manufacturers, but they remain subject to reporting requirements from 2026. Goodwinlaw noted that stewards must establish cybersecurity policies and cooperate with market-surveillance authorities, though their full compliance framework will take effect in 2027. The regulation also clarifies that companies using open-source software commercially may be deemed manufacturers, subject to the full CRA regime.

You may also like