Manufacturers selling products with digital components in the European Union must now report actively exploited vulnerabilities to cybersecurity authorities within 24 hours, according to new mandatory reporting rules under the Cyber Resilience Act that took effect September 11. The regulation applies to all manufacturers of products with digital elements made available in the EU, regardless of where those companies are based. The reporting duties aim to accelerate manufacturers' responses to security flaws while giving businesses a better understanding of their software supply chains.
Under Article 14 of the CRA, manufacturers must submit an early warning within 24 hours of learning about an actively exploited vulnerability, followed by a more detailed notification within 72 hours. The same time limits apply to severe incidents that affect the security of products with digital elements. After that, manufacturers must provide a final report on an actively exploited vulnerability within 14 days of making a fix or mitigation available. For serious incidents, the final report is due one month after the first report. Both EU and non-EU manufacturers must file these reports through ENISA's Single Reporting Platform, addressing them to the coordinating computer security incident response team determined under the CRA. Manufacturers must also inform affected users about actively exploited vulnerabilities or severe incidents, and tell them about available corrections or mitigations without undue delay. Failures to comply with these reporting duties could lead to fines reaching €15 million ($17.4 million) or 2.5 percent of the offender's annual turnover, whichever is higher.
Darren Anstee, CTO for security at Netscout, said the reporting deadlines introduce much-needed urgency in working toward global cyber resilience. "The 24-hour window in which an initial warning must be reported creates a level of urgency," he said, adding that subsequent deadlines ensure the gathering and release of additional information is prompt. Eran Kinsbruner, vice president of product marketing at Checkmarx, noted that what this means for manufacturers is that secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list. He added that modern applications are assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components, and increasingly AI models and services all interconnected.
The new rules aren't just designed to speed up manufacturers' responses to security flaws. With the reporting clock starting as soon as manufacturers become aware of an issue, they can't afford to begin mapping an affected product only after a vulnerability or incident emerges. They need a comprehensive view of the affected product and any related products that may share the flaw if they're to meet the deadlines. Furthermore, those requirements demand that manufacturers maintain this understanding throughout each product's lifecycle. Creating a software bill of materials when a product is launched is one thing, but maintaining that security snapshot over time is intended to help reduce the number and impact of serious cyberattacks across the EU. Most remaining CRA provisions become applicable on December 11, 2027, at which time manufacturers will also be required to embed security by design and default—meaning no default passwords and security updates are no longer optional.
Lawyers warn that manufacturers, particularly those outside heavily regulated sectors, must now contend with a growing body of overlapping rules. Heidi Waem, data, privacy, and cybersecurity partner at DLA Piper, said the CRA is arriving as organizations are already grappling with a growing body of Digital Decade legislation, including NIS2, DORA, the Data Act, and the AI Act. The compliance challenge for many businesses is evolving beyond understanding single regulations in isolation to determining how multiple frameworks interact, where requirements overlap, and how compliance programs can be coordinated across them. John Magee, partner and global co-chair of data, privacy, and cybersecurity at the same law firm, added that many still associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements. For compliance teams already very busy managing multiple Digital Decade initiatives, there's a risk that this first wave of CRA obligations has arrived sooner, and with a wider impact, than they had expected. The tightest compliance window now sits at the intersection of threat detection and regulatory obligation, where the cost of delay compounds across both security exposure and potential penalties. Companies that treat vulnerability disclosure as a communications exercise rather than an operational imperative will find the new regime unforgiving.

