The EU’s newest cybersecurity law switches on its hardest obligation first, and in the wrong order.
On 11 September 2026, the reporting duties of the Cyber Resilience Act (Regulation (EU) 2024/2847) start to bite. From that date, any manufacturer of a “product with digital elements” sold in the EU must report actively exploited vulnerabilities and severe incidents to Europe’s cybersecurity authorities on a fixed clock: an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days of a fix.
The rest of the Act, the part that actually requires products to be secure, does not apply until 11 December 2027. That is the design obligation: essential cybersecurity requirements, secure-by-default configuration, a conformity assessment, an EU declaration of conformity and the CE mark. Fifteen months separate the two dates.
Read in sequence, the order is backwards. For more than a year, manufacturers owe a legal duty to disclose that their products are being attacked, on products the same law has not yet required them to build securely.
What actually triggers the clock
The obligation is narrow and specific, which is where most of the confusion starts. It is not “report every bug.” The Act defines an actively exploited vulnerability as one for which there is reliable evidence that a malicious actor has exploited it in a system without the owner’s permission. Good-faith research, testing and coordinated disclosure are carved out. The trigger is evidence of real exploitation in the wild, not the mere existence of a flaw.
That definition sets a high bar and a hard question. “Reliable evidence” of exploitation is exactly what a manufacturer without mature telemetry does not have. The firms most likely to miss the trigger are the smaller vendors, the ones shipping connected consumer hardware, that the CRA was written to discipline. The 24-hour clock starts when the manufacturer becomes aware, so the practical incentive is to see as little as possible, which is the opposite of what the law intends.
Who files is also broader than it looks. The duty lands on the manufacturer, a role rather than a size. A firm that puts its name on a white-labelled device, or that substantially modifies someone else’s product, is the manufacturer for CRA purposes. Open-source stewards acting commercially get a lighter regime, but the party placing the product on the market carries the reporting duty.
One platform, many recipients
The mechanism is a single front door with several rooms behind it. ENISA is building a Single Reporting Platform, live for the September date, so a manufacturer reports once. Behind it, the notification goes first to the CSIRT designated as coordinator in the country of the manufacturer’s main establishment, which shares it without delay with the other national CSIRTs where the product is sold, and ENISA receives it at the same time.
The “report once” promise is real for the filer and misleading about what happens next. A single 24-hour notice can propagate to dozens of national teams and the EU agency in the same moment. A delegated act adopted in December 2025 lets a CSIRT withhold onward sharing on narrow cybersecurity grounds, for instance when disclosure would help attackers before a patch exists. That is a sensible valve, but it also means the manufacturer loses control of the blast radius the instant it files.
How it stacks against the rules already running
The CRA does not arrive on an empty field. NIS2 (Directive (EU) 2022/2555) already imposes a near-identical 24-hour and 72-hour cadence, but on a different subject: essential and important entities reporting operational incidents that disrupt their services. NIS2 is about the operator running the service. The CRA is about the product itself, and the manufacturer who made it. One event, a hospital’s connected device exploited in an attack, can now generate two separate reporting duties, on two legal bases, from two different parties, into overlapping authorities.
Then there is liability. The revised Product Liability Directive (Directive (EU) 2024/2853), which member states must transpose by December 2026, treats software as a product and treats a missing security update as a possible defect. A manufacturer that files a CRA notice admitting an actively exploited vulnerability is, in the same act, creating a dated, official record that its product carried a security flaw. That record does not prove liability, but it is precisely the kind of evidence a claimant under the new directive would want.
The implication
The sequencing is not an accident, and its defenders have a case: visibility into real-world exploitation is useful even before the market is fully secured, and standing up a reporting pipe is faster than certifying every product. Regulators want the telemetry now.
But the effect on the manufacturer is a fifteen-month window of asymmetric exposure. The duty to confess arrives before the duty to build well, and it lands beside a liability regime that treats the confession as evidence and a separate directive that may demand a parallel report. The firms that handle this cleanly will be the ones already instrumented to detect exploitation and already documenting their fixes. For everyone else, the first thing the Cyber Resilience Act makes mandatory is not resilience. It is disclosure.
Discussion
Sign in to join the discussion.
No comments yet. Be the first to share your thoughts.