Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-11 ยท updated: 2026-09-11 ยท tags: [incident, regulation, eu, cyber-resilience-act, enisa, reporting, compliance] ยท confidence: high ยท severity: medium ยท affected_sectors: [technology, government, legal-services] ยท au_impact: true

From 11 September 2026, organisations that sell products with network connectivity anywhere in the EU must report actively exploited vulnerabilities and severe security incidents affecting those products to ENISA's Single Reporting Platform within 24 hours, with a fuller notification within 72 hours, a formal report once a fix is available, and a final report within a month. The obligation applies regardless of where the vendor is based; only already EU-regulated technologies and open-source software are out of scope. Fines reach โ‚ฌ15 million or 2.5% of worldwide annual turnover.

Attribute Detail
Instrument EU Cyber Resilience Act (Regulation (EU) 2024/2847)
In force (reporting) 2026-09-11 (fast-tracked, ahead of the rest of the CRA)
Reporting body ENISA Single Reporting Platform
Deadlines 24h initial, 72h fuller notification, fix report, final report within a month
Penalties Up to โ‚ฌ15m or 2.5% of worldwide annual turnover
Exemptions Microenterprises (<10 staff, <โ‚ฌ2m) and small enterprises (<50 staff, <โ‚ฌ10m) exempt from the 24h penalty
Remainder deferred SBOMs, vulnerability handling, risk assessment enforced from December 2027

Notable gaps: the CRA imposes no reporting duty for known-but-not-yet-exploited vulnerabilities however severe, and Article 16(2) allows dissemination of a notification to be delayed on justified cybersecurity-sensitivity grounds at the manufacturer's request. This directly affects Australian and New Zealand software exporters whose network-connected products are sold into the EU, and it lands the same week as the US FTC's rescission of the Biden-era health-app breach-notification policy โ€” a regulatory divergence that Five Eyes privacy regulators will have to navigate. See eu-publishes-draft-cyber-resilience-act-standards-for-product-vendors.md for the standards work that preceded it.