The European Union has entered the first reporting phase of its Cyber Resilience Act, introducing new obligations for manufacturers of products with digital elements to report actively exploited vulnerabilities and severe security incidents within strict deadlines.
The first phase took effect on September 11, 2026, ahead of the Act becoming fully applicable in December 2027.
Proposal for Conducting Cyber Crisis Drill, Tabletop Exercise (TTEx) & CCMP Readiness Exercise
What Has Changed Under the Cyber Resilience Act?
Manufacturers covered by the new rules must report actively exploited vulnerabilities and severe incidents affecting the security of their products.
The reporting process is designed to give authorities early information about significant cyber risks while allowing manufacturers to continue investigating an incident. The rules apply before the wider Cyber Resilience Act becomes fully applicable.
The reporting mechanism operates through a platform involving the European Union Agency for Cybersecurity, ENISA, and the relevant national Computer Security Incident Response Teams, or CSIRTs.
How Quickly Must Companies Report?
The first major challenge is the speed required for reporting. Manufacturers may have to submit an early notification within 24 hours after becoming aware of an actively exploited vulnerability.
A more detailed notification follows within 72 hours. The early report is not expected to contain every technical detail because an investigation may still be under way, but companies must still provide useful information within a short period.
This creates a practical challenge for manufacturers because they need to identify what happened, determine whether the incident falls within the reporting rules and organise an official response while the technical investigation is continuing.
What Information Must Manufacturers Provide?
The reporting requirements can involve information about the affected product, the nature of the vulnerability or incident and available details about its impact.
Companies may also need information on product architecture, configuration and deployment to understand the incident and provide authorities with meaningful details.
This means manufacturers need more than an incident-response team. They must also know their products, software versions, dependencies and vulnerability-management processes well enough to quickly identify what has been affected.
Why Is the Reporting Process Difficult?
One challenge is deciding whether an incident meets the threshold for mandatory reporting. Manufacturers may need to make that decision while information is still incomplete.
Another challenge involves internal coordination. Security teams, legal teams, product teams and management may all need to work together within a very limited period.
Companies must also establish in advance who has authority to report an incident, which CSIRT is responsible, who can access the necessary systems and how responsibilities will be transferred outside normal working hours. With deadlines measured in hours, unclear internal procedures could slow the response.
How Do Other EU Cyber Rules Affect Reporting?
A single cyber incident may fall under several European regulatory regimes at the same time.
Depending on the organisation, product and circumstances, the same event could also create obligations under the NIS2 Directive or the General Data Protection Regulation.
The Cyber Resilience Act’s reporting system is intended to reduce duplication within its own framework by allowing manufacturers to submit a notification once, with relevant information subsequently shared with appropriate CSIRTs and ENISA.
However, companies may still have to understand how different European cybersecurity and data-protection rules apply to the same incident.
Why Could Smaller Companies Face Greater Pressure?
The reporting burden may be particularly significant for smaller manufacturers and organisations with limited product-security resources.
Companies need visibility across their product inventories, software versions, dependencies and vulnerability-management processes even before the Cyber Resilience Act becomes fully applicable in December 2027.
The European Commission has recognised implementation challenges and published practical guidance, including examples, flowcharts and specific attention to microenterprises and small and medium-sized businesses.
Why Does the New System Matter?
The reporting requirements mark a broader shift in cybersecurity regulation. Responsibility is moving beyond responding to attacks against networks and towards the security of digital products, software components and supply chains from the beginning.
Information about vulnerabilities is also becoming part of the regulatory system rather than remaining only a technical matter inside individual companies.
The effectiveness of the framework will depend partly on whether manufacturers, CSIRTs, ENISA and other relevant organisations can turn large amounts of vulnerability information into timely and useful cyber intelligence.
The wider impact may also extend beyond the EU if manufacturers begin treating European requirements as a common standard for secure product design, vulnerability disclosure and digital supply-chain governance.
The420 Insight
For manufacturers selling digital products in Europe, cybersecurity reporting is becoming a time-sensitive regulatory responsibility.
Companies need clear internal reporting authority, accurate product information and established incident procedures before a vulnerability emerges, because the first reporting deadline can arrive within 24 hours.
About the author — Ayesha Aayat writes on cybercrime, digital safety, and emerging online threats. Her work focuses on public awareness, legal clarity, and technology-driven risks.
Follow for daily updates on cybercrime, corporate fraud, DFIR, hacking, investigations, and digital forensics