Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Selling digital tech into the EU? The new Cyber Resilience Act will apply to you

Makers of “products with digital elements” sold in the EU now need to report security incidents within 24 hours.

Mon, 14 Sep 2026
Selling digital tech into the EU? The new Cyber Resilience Act will apply to you

Manufacturers of digital goods sold in the European Union must now operate under the EU’s Cyber Resilience Act (CRA), which lays out a tight time frame for reporting security incidents.

According to the reporting obligations, “the CRA requires manufacturers to notify actively exploited vulnerabilities and severe incidents having an impact on the security of their product with digital elements”.

“They need to submit an early warning within 24 hours of becoming aware, and a full notification within 72 hours. A final report needs to be submitted no later than 14 days after a corrective measure is available for actively exploited vulnerabilities and within a month from the 72-hour notification for severe incidents,” it said.

 
 

Under the CRA – which officially came into effect on 11 September – the EU defines products with digital elements as a “software or hardware product and its remote data processing solutions, including software or hardware components being placed on the market separately”.

The obligations will also apply to open-source products.

Nikhil Gupta, founder and CEO of security governance firm ArmorCode, said that a document that was once something to plan around has become a “clock they have to answer to”.

“Any manufacturer placing a product with digital elements on the EU market has to report an actively exploited vulnerability to ENISA within 24 hours of becoming aware of it. That’s not 24 business hours; it’s 24 hours, full stop, regardless of time zone or weekend,” Gupta said.

“This isn’t a voluntary framework like SOC 2 or ISO 27001 that a company can choose to pursue when it’s ready. It’s a legally binding EU regulation, and it applies even if a company is headquartered outside the EU. If your product is available on the EU market, today’s deadline applies to you.”

Gupta described the CRA as something more like a “cascade, not a single deadline”. Each stage requires a different degree of reporting, and missing one still means you must address the next requirement.

“The technical challenge isn’t finding vulnerabilities. Most organisations have plenty of scanners doing that already. The real challenge is that the information needed to file a CRA notification usually lives in five or six different places at once, SIEMs, threat feeds, KEV alerts, scanner findings, asset inventories, and SBOMs, none of which were built to talk to each other on a 24-hour clock,” Gupta said.

“A 24-hour reporting window leaves no room for manual coordination. If your process for confirming exploitation and drafting a notification depends on a security analyst finding the right spreadsheet and looping in product, legal, and compliance by email, you will lose hours you don’t have before you’ve even started writing the report.”

According to Gupta, while many companies have tried to deliver products to assist with reporting, most of these are bolt-ons to existing reporting tools or scanners without a complete workflow picture.

“None of those alone gets a company through a 24-hour reporting requirement, because the clock doesn’t wait for someone to move data from one tool to another,” Gupta said.

“Organisations should think about this as an extension of vulnerability management. The same exploit intelligence, asset context, and prioritisation logic that tells you what to fix first is exactly what tells you what you’re now legally required to report, and on what timeline. Companies that already have strong exposure management practices are going to find CRA compliance far less disruptive than companies starting from zero today.”

Louise Horton, government affairs lead at cyber security firm the NCC Group, said the new requirements will be, for many organisations, their “first real test of operational readiness”.

“Those that are most prepared will have already embedded secure-by-design principles into product development and established strong governance across their software and supply chains,” Horton said.

“Rather than treating compliance as a series of isolated obligations, organisations should view these requirements as part of a broader cyber resilience strategy.

“With the full requirements of the Cyber Resilience Act due to apply from December 2027, the message is clear: the implementation phase is now well underway, and organisations can no longer afford to defer preparation.”

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: