Skip to main content
Compliance

EU Enforces Cyber Resilience Act with 24-Hour Vulnerability Reporting Rule

Formal meeting room with laptop and papers on a table.

"The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," said Darren Anstee, CTO for security at Netscout.

Article 14: the 24‑hour clock starts today

As of today, Article 14 of the EU's Cyber Resilience Act (CRA) is applicable: manufacturers selling products with digital elements made available in the EU must report actively exploited vulnerabilities to cybersecurity authorities. Subject to the regulation's exemptions, the duty applies irrespective of where a manufacturer is based. The law requires an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours. The same 24‑ and 72‑hour deadlines apply to severe incidents affecting product security.

Final reports, users, and timing differences

The CRA sets distinct deadlines for the final reports. For an actively exploited vulnerability, manufacturers must provide a final report within 14 days of making a corrective or mitigating measure available. For serious incidents, the final report is due one month after the first report. Manufacturers must also inform affected users, where appropriate, and the CRA states that users must be told of available corrections or mitigations without undue delay.

ENISA's Single Reporting Platform and CSIRT coordination

All EU and non‑EU manufacturers must submit reports through ENISA's Single Reporting Platform (SRP). Notifications are addressed to the coordinating computer security incident response team (CSIRT) determined under the CRA. For an EU manufacturer, that is generally the CSIRT for the member state where the manufacturer has its main establishment; separate rules determine the coordinator for manufacturers based outside the bloc.

What this means for manufacturers, security teams, and compliance lawyers

  • Manufacturers: The reporting clock forces a continuous, up‑to‑date view of each product's software composition and related products, not just a one‑time bill of materials created at launch.
  • Security teams and technologists: Rapid sharing is intended to let organisations put defences and mitigating controls in place when there is heightened risk, a benefit Netscout's Darren Anstee highlighted as improved global cyber resilience.
  • Compliance lawyers and procurement teams: Law firms warn that CRA obligations arrive amid overlapping Digital Decade legislation — including NIS2, DORA, the Data Act, and the AI Act — complicating coordination across frameworks, as Heidi Waem of DLA Piper observed.

Traceability, SBOMs, and design obligations ahead

The CRA is designed not only to speed reporting but to change how manufacturers understand and track their software supply chains. The regulation requires that manufacturers maintain traceability throughout a product's lifecycle; creating a software bill of materials (SBOM) at launch will not be sufficient in the long run. The SBOM becomes mandatory when most remaining CRA provisions take effect on December 11, 2027. At that time, manufacturers will also be required to embed security by design and by default — the law explicitly calls out no default passwords and makes security updates mandatory rather than optional — and products will need to pass the applicable conformity assessment before being placed on the EU market and bearing a CE mark. As Eran Kinsbruner, veep of product marketing at Checkmarx, put it, “Organizations need to understand these components, their dependencies and the risks they introduce.”

Penalties and the regulatory squeeze

Failures under the CRA are punishable by tiers of fines, the most serious reaching €15 million or 2.5 percent of the offender’s annual turnover, whichever is higher. The reporting duties that took effect today are classified as core responsibilities under the act, meaning non‑compliance with these deadlines could lead to the maximum fines being issued. Lawyers warn the breadth and timing of obligations may catch some organisations off guard: “Many still associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements,” John Magee, partner and global co‑chair of data, privacy, and cybersecurity at DLA Piper, said.

The immediate effect is procedural: a 24‑hour clock to alert authorities, a 72‑hour follow‑up, and stricter recordkeeping and traceability demands. The longer effect is structural: manufacturers will need ongoing, lifecycle‑level visibility into software components, dependencies and mitigations — and, for many, coordinated compliance programmes that sit across multiple EU digital regulations. With most of the CRA’s heavy lifting scheduled for December 11, 2027, organisations have a defined runway to build those capabilities — and regulators now have a faster route to the information they say they need to protect users and the market.

Original story at The Register