Berlin: Germany’s federal information-security agency, the BSI, has spent much of the spring stress-testing the technical and organisational rails that will carry European Cyber Resilience Act vulnerability reports starting in September 2026, and the dry runs are surfacing the kind of operational frictions that legislators rarely anticipate. The reporting obligations, which apply roughly fifteen months before the substantive product-security requirements of the Act, mark the first concrete compliance milestone for a regulation that will eventually touch every product with digital elements shipped into the single market.
From 11 September 2026, manufacturers of connected products will be required to file an early-warning notification within twenty-four hours of becoming aware of an actively exploited vulnerability, a fuller report within seventy-two hours, and a final report once a corrective measure becomes available, with a fourteen-day window for that final step in the case of actively exploited vulnerabilities. Severe security incidents impacting product availability or integrity attract their own twenty-four-hour clock. The reports flow through a Single Reporting Platform operated jointly by the European Union Agency for Cybersecurity, ENISA, and national Computer Security Incident Response Teams, with information shared in near real time across the network.
The scope is unusually broad. Software, hardware, embedded systems, Internet-of-Things devices, industrial control systems, networking equipment, and a substantial portion of medical and industrial machinery all fall within the Act’s perimeter, and importantly, the reporting obligation applies to legacy products still on the market. For manufacturers whose engineering organisations were built around national vulnerability-disclosure norms, the harmonised European clock and the cross-border information-sharing architecture represent a structural change in incident response. Few have a software bill of materials sufficiently mature to underpin the kind of automated detection that the timelines effectively require.
National designations are still in motion. Member States are working through which authority will host their national CSIRT for CRA purposes, how it will interface with sectoral regulators such as those for medical devices or radio equipment, and how penalties for non-reporting or late reporting will be administered alongside existing obligations under the Network and Information Security Directive. The German federal office’s preparatory consultations with industry have surfaced concerns about double reporting, particularly for entities already subject to incident-notification duties under the NIS2 regime, and the Commission is expected to issue guidance reconciling the two frameworks before the September deadline.
For consumer-facing manufacturers, the public dimension of the regime is the second axis of disruption. Once vulnerabilities are reported through the Single Reporting Platform, ENISA may make information about exploited vulnerabilities available where doing so serves public protection, and national authorities will retain transparency tools of their own. The risk of premature disclosure of unpatched vulnerabilities is the principal concern raised by industry associations, who argue that the Act’s twenty-four-hour early-warning window does not always align with the realistic timeline for coordinated remediation. Civil-society groups counter that consumers have a legitimate interest in knowing when a product they own is actively under attack.
The substantive product-security requirements of the Act, including secure-by-default settings, vulnerability handling across the support period, and the prohibition on shipping products with known exploitable vulnerabilities, apply from 11 December 2027. Whether the September 2026 reporting deadline functions as a soft launch or a hard cliff will depend on enforcement appetite during the gap year.




