REG-007

Cyber Resilience Act vulnerability reporting starts

11 September 2026

in 6 days

Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents to their CSIRT and to ENISA, on a clock measured in hours, more than a year before the rest of the regulation applies.

The sentence that fixes the date

This Regulation shall apply from 11 December 2027. However, Article 14 shall apply from 11 September 2026.

Regulation (EU) 2024/2847, Article 14, per Article 71Regulation (EU) 2024/2847, OJ text

Who is forced to spend

Who

Every manufacturer selling hardware or software with digital elements into the EU, including firms whose product is a library or a component.

What they spend today

Incident reporting is handled by hand today: a security lead, a shared inbox and a spreadsheet of who to notify in which jurisdiction.

Sector

Software and connected hardware

No dossier yet for this catalyst.

Dossier 001 is open end to end, free, so you can see exactly how deep a dossier goes before this one exists.