EU Cyber Resilience Act forces manufacturers to report exploits within 24 hours
The EU's Cyber Resilience Act now obliges makers of digital products to alert ENISA of actively exploited flaws within 24 hours and follow up with detailed reports.
From today, the EU Cyber Resilience Act activates mandatory reporting duties for all manufacturers of products containing digital elements that are placed on the EU market, irrespective of where the firms are based. Under Article 14, companies must submit an early-warning notice to ENISA’s Single Reporting Platform within 24 hours of learning of an actively exploited vulnerability, a detailed report within 72 hours, and a final report within 14 days after a corrective measure is available; severe incidents follow a similar timetable with a one-month final-report deadline.
The rules also require informing users of available corrections without undue delay. Failure to comply can trigger fines of up to €15 million or 2.5 % of the offender’s yearly turnover. Industry experts such as Darren Anstee of Netscout and Eran Kinsbruner of Checkmarx say the tight deadlines should boost cyber resilience, while lawyers Heidi Waem and John Magee warn the CRA adds to an already crowded EU digital-regulation landscape. The act paves the way for further obligations, including security-by-design and mandatory software bills of materials by late 2027.
Why it matters
Faster vulnerability reporting aims to protect EU users and pressure manufacturers to improve product security.
In this story
