• EU Cyber Resilience Act reporting duties start on 11 September
  • Manufacturers have 24 hours for the first warning and 72 hours for a fuller report

The fact

EU Cyber Resilience Act reporting duties took effect on 11 September, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents affecting product security. An early warning is due within 24 hours of becoming aware of a reportable event.

A fuller notification follows within 72 hours. The final deadline then depends on the event. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final report is due within one month of the 72-hour notification and must cover the incident, its impact, likely cause and measures taken or planned.

Reports go through ENISA's Single Reporting Platform to the relevant national CSIRT, with information generally made available to ENISA at the same time. The duties apply to manufacturers rather than imposing the same reporting obligation on every customer using the product. The Act also addresses notifying affected users and providing information on corrective or mitigating measures. Most of its wider product requirements apply from December 2027.

The assessment

Once a manufacturer knows that a vulnerability is being actively exploited, it may have to report the problem before engineers fully understand it. The first 24-hour warning could therefore go out before every affected version has been identified or a fix has been tested. More detail follows after 72 hours, while the technical investigation continues.

In practice, reporting and remediation will often happen at the same time. Manufacturers need to tell regulators what they know without presenting early assumptions as settled findings. Meanwhile, their customers need enough information to decide whether they are affected and whether any immediate action is necessary.

For BTW readers, what matters is how quickly that first warning develops into useful guidance. Operators need clear information on affected versions, safe mitigations and, eventually, a supported fix. Meeting the reporting deadline is important, but customers still have to know what to do with the equipment they are running.

What to watch

Watch whether supplier advisories clearly separate confirmed facts, provisional findings and available mitigations after the first warning. Version-specific guidance, updates following the 72-hour notification and a clear path to a supported fix will show whether the new timetable is helping operators make maintenance decisions rather than simply producing timely regulatory filings.