> ## Content Index
> Fetch the complete content index at: https://unhyd.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# EU Cyber Resilience Act Reporting Starts Today
- URL: https://unhyd.com/article/eu-cyber-resilience-act-reporting-obligations-start/
- Published: 2026-09-11T13:06:44.000Z
- Updated: 2026-10-01T19:38:57.000Z
- Description: Manufacturers of covered software and connected hardware now face new EU deadlines for reporting actively exploited vulnerabilities and severe security incidents.
- Author: Jonas Muthoni
- Tags: Technology, Business, #unhyd-import, #sidebar-popular-posts

**EU Cyber Resilience Act reporting** has reached its first live deadline. From 11 September 2026, manufacturers of covered products with digital elements must report actively exploited vulnerabilities and severe incidents affecting product security through the European Union's new reporting system.

The date matters because it comes well before most of the Cyber Resilience Act's wider obligations. Those main requirements are due to apply from 11 December 2027\. But Article 14, the provision on incident and vulnerability reporting, applies now. For companies that make connected hardware or software for the EU market, incident response is no longer only an internal engineering and communications exercise; in defined cases, it now carries a reporting duty.

## What EU Cyber Resilience Act reporting requires

The rule is not a mandate to report every bug. It covers an *actively exploited vulnerability* in a product with digital elements, as well as a *severe incident* that affects the product's security. In either case, the manufacturer must use the Cyber Resilience Act Single Reporting Platform, which is operational from today.

The first step is an early warning. It must be submitted without undue delay and, at the latest, 24 hours after the manufacturer becomes aware of the relevant vulnerability or incident. The follow-up notification is due within 72 hours. The information is routed to the Computer Security Incident Response Team for the manufacturer's main establishment and, except in exceptional circumstances, made available to the EU Agency for Cybersecurity, ENISA.

The final deadline depends on what is being reported. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the Commission says the final report is due within one month of the 72-hour notification. That distinction is worth building into an incident-response playbook now rather than trying to resolve it during a live security event.

## Why this changes the operational picture

Security teams already have a familiar rhythm for discovery, triage, mitigation and customer communication. The new obligation adds a formal external reporting track to particular cases. That means a manufacturer needs a reliable way to decide whether a flaw is being actively exploited, establish when it became aware of the issue, identify the product and markets involved, preserve the details required for the report, and coordinate engineering and legal decisions quickly.

The deadline is also a reason to separate vulnerability management from generic compliance checklists. A team may have a process for patching a defect, but it may not have a named owner for assessing whether an exploit has crossed the reporting threshold or for submitting an early warning before a full technical picture is available. The 24-hour clock makes that gap visible.

For buyers of connected products, the practical implication is less immediate but still relevant. The Act is designed to improve the security lifecycle of hardware and software sold in the EU, including how manufacturers handle vulnerabilities. It does not mean every future disclosure will be public at once. The regulation permits coordination around disclosure, while the Commission's reporting guidance explains that the platform sends a report to the appropriate national CSIRT and ENISA.

## What is not in force yet

Today is not the date on which every Cyber Resilience Act obligation applies. The Commission says the main requirements, including many product cybersecurity and conformity obligations, apply from 11 December 2027\. The Commission's reporting page also notes that the reporting obligation for open-source software stewards under Article 24(3) begins on that later date. That timing matters: readers should not mistake the first reporting deadline for full implementation of the entire regulation.

Nor is this a substitute for careful scope analysis. Whether a company, product, vulnerability or incident falls within the relevant provisions depends on the facts. The useful immediate task is more practical: make sure the people who run security response, product, legal and communications can recognize a potentially reportable event and have a tested route into the Single Reporting Platform.

The broader direction is clear. EU Cyber Resilience Act reporting makes the speed and quality of a manufacturer's vulnerability response part of a regulatory obligation. For companies that are also deploying action-taking software, that reporting discipline belongs beside secure design and access controls; Unhyd's [guide to permission-first AI agent security](https://unhyd.com/article/ai-agent-security-permission-first-guide/) explains why narrow permissions and auditable actions matter as software systems take on more responsibility.

## Sources

- [European Commission: Cyber Resilience Act reporting obligations](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting?ref=unhyd.com)
- [Regulation (EU) 2024/2847, Article 14 and Article 71](https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32024R2847&ref=unhyd.com)
- [European Commission: Cyber Resilience Act overview](https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act?ref=unhyd.com)