From 11 September 2026, organisations that sell products with network connectivity anywhere in the EU must report actively exploited vulnerabilities and severe security incidents affecting those products to ENISA's Single Reporting Platform within 24 hours, with a fuller notification within 72 hours, a formal report once a fix is available, and a final report within a month. The obligation applies regardless of where the vendor is based; only already EU-regulated technologies and open-source software are out of scope. Fines reach โฌ15 million or 2.5% of worldwide annual turnover.
| Attribute | Detail |
|---|---|
| Instrument | EU Cyber Resilience Act (Regulation (EU) 2024/2847) |
| In force (reporting) | 2026-09-11 (fast-tracked, ahead of the rest of the CRA) |
| Reporting body | ENISA Single Reporting Platform |
| Deadlines | 24h initial, 72h fuller notification, fix report, final report within a month |
| Penalties | Up to โฌ15m or 2.5% of worldwide annual turnover |
| Exemptions | Microenterprises (<10 staff, <โฌ2m) and small enterprises (<50 staff, <โฌ10m) exempt from the 24h penalty |
| Remainder deferred | SBOMs, vulnerability handling, risk assessment enforced from December 2027 |
Notable gaps: the CRA imposes no reporting duty for known-but-not-yet-exploited vulnerabilities however severe, and Article 16(2) allows dissemination of a notification to be delayed on justified cybersecurity-sensitivity grounds at the manufacturer's request. This directly affects Australian and New Zealand software exporters whose network-connected products are sold into the EU, and it lands the same week as the US FTC's rescission of the Biden-era health-app breach-notification policy โ a regulatory divergence that Five Eyes privacy regulators will have to navigate. See eu-publishes-draft-cyber-resilience-act-standards-for-product-vendors.md for the standards work that preceded it.