Athens: The countdown that manufacturers of internet-connected products have watched warily for two years is entering its decisive phase. Under the Cyber Resilience Act, which took effect in December 2024, the first hard obligations are now landing on a fixed calendar, and the most demanding of them is barely a hundred days away.
From 11 September, makers of products with digital elements, a category that stretches from smart doorbells and routers to industrial sensors and software libraries, must notify authorities of actively exploited vulnerabilities and severe incidents. The clock is unforgiving. An initial alert is due without undue delay and in any case within 24 hours of the manufacturer becoming aware, a follow-up within 72 hours, and a final report either within 14 days of a fix becoming available for an exploited vulnerability or within a month of the 72-hour update for a severe incident. Reports flow to national authorities and the EU cybersecurity agency through a shared platform.
The reporting regime is only the leading edge. Since 11 June the provisions governing how conformity assessment bodies are notified have applied, laying the institutional plumbing that will later certify whether products meet the Act’s security requirements. Those substantive requirements, covering secure design, vulnerability handling and security updates across a product’s expected lifetime, become binding on 11 December 2027, giving industry a runway to redesign hardware and firmware.
For manufacturers the immediate task is organisational rather than technical. Meeting a 24-hour notification duty demands monitoring systems that can detect exploitation quickly, legal and engineering staff who can classify an incident under pressure, and rehearsed procedures for filing within jurisdictions that have little tolerance for delay. Firms accustomed to disclosing flaws on their own timetable, or not at all, face a cultural adjustment as much as a compliance one.
The reach of the rules extends well beyond European borders. A component supplier in Asia or a software vendor in North America that places products on the EU market falls within scope, which is why the Act is already influencing product security practices globally. Open-source maintainers, initially alarmed that volunteer projects might shoulder corporate-style duties, secured lighter treatment, though the boundaries of those carve-outs will be tested in practice.
Regulators frame the law as a response to a market that has long rewarded speed to release over security, leaving households and businesses exposed to devices that ship with known weaknesses and receive no updates. Critics warn that aggressive reporting timelines could flood authorities with alerts of uneven quality, and that smaller manufacturers may struggle with the administrative load. The next test comes in September, when the first mandatory disclosures reveal whether Europe’s ambition to make connected products secure by design translates into a workable routine or a paperwork bottleneck.




