Cyber Resilience Act Reporting Obligations Will Take Effect in September

The entry into force of the reporting obligations under the Cyber Resilience Act is approaching.

From 11 September 2026, manufacturers must report any actively exploited vulnerabilities in their products and severe incidents having an impact on the security of the product that come to their attention. The report must be submitted to ENISA’s Single Reporting Platform within 24 hours (and thereafter updated in intervals as defined in the CRA), and to the users of the product.

The reporting obligation applies broadly to various devices, software products, and industrial systems. It also extends to cloud services where such services form part of a product or of a remote data-processing solution provided by the manufacturer.

The other obligations under the Cyber Resilience Act will enter into force later, but organizations should begin preparing for them well in advance.

For more information on cyber resilience requirements: Upcoming Cyber Resilience Requirements

 

Related Services

AI, Data & Privacy
Commercial Contracts

Latest News