EU Cyber Resilience Act's 24-hour vulnerability reporting rule takes effect

Manufacturers must report actively exploited flaws within a day or face fines up to €15 million

edit
By LineZotpaper
Published
Read Time2 min
Manufacturers of products with digital elements sold in the EU are now legally required to report actively exploited vulnerabilities within 24 hours, under Article 14 of the EU Cyber Resilience Act (CRA). The mandatory reporting rules became applicable today, applying to both EU and non-EU manufacturers. Failure to comply can result in fines of up to €15 million or 2.5% of annual turnover.

The new obligations under Article 14 require manufacturers to submit an early warning to cybersecurity authorities within 24 hours of becoming aware of an actively exploited vulnerability. A more detailed notification must follow within 72 hours, and a final report on corrective measures must be filed within 14 days of making a fix available. For severe security incidents, the final report deadline is one month after the initial report.

Reports must be submitted through ENISA's Single Reporting Platform (SRP) to the coordinating computer security incident response team (CSIRT). EU-based manufacturers report to their home member state's CSIRT, while separate rules determine the coordinator for non-EU manufacturers. Manufacturers are also required to inform affected users about vulnerabilities and available mitigations without undue delay.

Darren Anstee, CTO for security at Netscout, said the deadlines introduce needed urgency. "The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said. "Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk."

The reporting duties are classified as core CRA responsibilities, meaning non-compliance can trigger maximum fines. These rules are part of a phased rollout of the Act; most remaining provisions, including requirements for security by design, no default passwords, and mandatory security updates, become applicable on December 11, 2027. At that point, covered products must also undergo conformity assessments and bear a CE mark.

The CRA also aims to improve software supply chain visibility. The tight reporting deadlines mean manufacturers must maintain a comprehensive understanding of their products and any related items sharing vulnerabilities throughout the product lifecycle – a requirement that will eventually include producing a software bill of materials (SBOM).

§

Analysis

Why This Matters

  • Manufacturers worldwide selling connected devices in the EU face immediate compliance pressure and potential fines for slow vulnerability disclosure.
  • The 24-hour clock forces companies to maintain real-time awareness of their software supply chains, accelerating security patch cycles globally.
  • Creates a precedent that could influence cybersecurity regulation in other jurisdictions seeking similar rapid-reporting mandates.

Background

The EU Cyber Resilience Act (CRA) was designed to improve cybersecurity for hardware and software sold in the European Union by establishing mandatory security requirements throughout a product's lifecycle. Article 14's reporting duties are the first major enforceable component. The Act has been phased in over several years, with the most significant obligations – including security-by-design requirements and CE marking – due to take full effect in December 2027.

Key Perspectives

Manufacturers (EU and non-EU): Must now operationalise 24/7 vulnerability monitoring and establish procedures for filing reports to ENISA's platform within tight windows. Non-compliance risks fines of up to €15 million or 2.5% of annual turnover. Cybersecurity authorities and industry experts: Welcome faster information sharing as a tool for collective defence. Netscout's Darren Anstee called the deadlines a driver of global cyber resilience. Smaller manufacturers: May face disproportionate compliance costs, particularly if they lack dedicated security teams or robust SBOM processes. The phased timeline gives some runway, but the 24-hour reporting requirement is already in effect.

What to Watch

  • Early enforcement actions by EU member state CSIRTs against non-compliant manufacturers.
  • Adoption of ENISA's Single Reporting Platform and any teething issues in cross-border coordination.
  • December 11, 2027: when most remaining CRA provisions become applicable, including mandatory security-by-design and CE marking.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.