Every company selling a networked device, connected component, or software product into the European Union faces a binding new deadline: beginning September 11, 2026, manufacturers must file an early warning with EU cybersecurity authorities within 24 hours of detecting an actively exploited vulnerability in any product on the EU market. Today, June 11, marks the first formal milestone in the CRA's phased rollout — the date on which national authorities were required to designate conformity assessment bodies under the law's Chapter IV — and the window to complete the internal pipeline work that makes 24-hour compliance possible is now measured in weeks, not months. The regulation driving this change is the EU Cyber Resilience Act (Regulation EU 2024/2847), which entered into force on December 10, 2024, and covers virtually any hardware or software product that connects directly or indirectly to a device or network. Consumer smart speakers, home routers, industrial control systems, enterprise software suites, and connected vehicle telematics units are all in scope. Non-compliance can result in product withdrawal from the EU's 450-million-person single market and financial penalties of up to €15 million or 2.5% of global annual turnover, whichever is higher. The most immediate challenge for vendors is not what the regulation requires — the requirements are now clearly documented — but whether the internal engineering, legal, and security operations infrastructure exists to meet a 24-hour notification clock that starts the moment an organization becomes aware of an exploitation, not when it has confirmed or analyzed it. CRA Vulnerability Reporting: What the 24-Hour Pipeline Requires Under Article 14 of the CRA, manufacturers must submit notifications through the ENISA Single Reporting Platform (SRP), a centralized EU web portal that routes each submission simultaneously to the national Computer Security Incident Response Team (CSIRT) of the manufacturer's main EU establishment and
EU Cyber Resilience Act: 24-Hour Vulnerability Clock Starts September 11 for <b>IoT</b> Vendors
Read the original article
techtimes.com →