FROM 11 September 2026, the EU’s Cyber Resilience Act (CRA) introduces binding, rapid reporting requirements for organisations selling products in EU member states. If a vendor discovers actively exploited vulnerabilities or a severe security incident affecting a product, they must report to ENISA via the Single Reporting Platform (SRP) within 24 hours. A more detailed notification, covering severity, impact and recommended mitigations, is then due within 72 hours.
When a fix becomes available, a subsequent security report must be submitted within a couple of weeks, and a final, comprehensive report within a month. Firms that fail to report could face penalties up to €15 million or 2.5% of worldwide annual turnover, whichever is higher. Exemptions apply to micro and some small enterprises, reflecting a proportionate approach to enforcement.
The CRA targets organisations that sell network-connected hardware and software in the EU, regardless of where the company is based, with a broad scope that excludes only certain EU-regulated technologies and some open source software. Known but not yet actively exploited vulnerabilities are not subject to these reporting duties. The act also provides limited discretion to delay notifications in exceptional circumstances for justified cybersecurity reasons.
Industry commentary suggests the penalties are intended to drive improved incident detection and response, though practical enforcement may resemble GDPR patterns, with actual fines often below the maximum. The CRA’s strict timelines and the ENISA reporting mechanism place a new compliance burden on vendors, while preserving a measured approach for smaller entities.