REG-007
Cyber Resilience Act vulnerability reporting starts
11 September 2026
in 6 days
Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to their CSIRT and to ENISA, on a clock measured in hours, more than a year before the rest of the regulation applies.
The sentence that fixes the date
This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026.
Regulation (EU) 2024/2847, Article 14, per Article 71 — Regulation (EU) 2024/2847, OJ text
The day it lands
11 September 2026
6
days remaining
Counted from the date in the official journal text linked on this page. Arithmetic, not a forecast.
Who is forced to spend
Who
Every manufacturer selling hardware or software with digital elements into the EU, including firms whose product is a library or a component.
What they spend today
Incident reporting is handled by hand today: a security lead, a shared inbox and a spreadsheet of who to notify in which jurisdiction.
Sector
Software and connected hardware
No dossier yet for this catalyst.
Dossier 001 is open end to end, free, so you can see exactly how deep a dossier goes before this one exists.