Brussels: The European Commission moved its landmark EU Cyber Resilience Act from paper to practice on 11 June 2026, when the first binding obligations took effect, leaving manufacturers of internet-connected products racing to meet a hard 11 September 2026 reporting deadline. The regulation forces companies that sell everything from smart doorbells to industrial software into the EU to build in security by design or face fines of up to €15 million or 2.5% of global turnover.
What changed this month
As of 11 June 2026, the rules on notifying conformity assessment bodies under Chapter IV of the EU Cyber Resilience Act began to apply, allowing national authorities to designate the independent labs that will certify whether a product meets the law’s essential cybersecurity requirements. It is the first concrete step in a phased rollout that the Commission has spread over three years to give industry time to adapt.
The more consequential change arrives on 11 September 2026, when manufacturers must start reporting actively exploited vulnerabilities and severe security incidents. Companies will have to file an early warning within 24 hours of becoming aware of a flaw, a fuller notification within 72 hours, and a final report once a fix is available.
- 11 June 2026: conformity assessment body rules apply.
- 11 September 2026: 24-hour and 72-hour vulnerability reporting begins.
- 11 December 2027: the full set of design and lifecycle obligations takes effect.
How reporting will work
Reports will flow through a single EU platform to the national Computer Security Incident Response Team where a firm has its main establishment, with the information shared simultaneously with the EU cybersecurity agency ENISA. The design is meant to spare companies from filing the same incident to multiple regulators, a persistent complaint during the negotiations.
The Commission frames the EU Cyber Resilience Act as the first horizontal law anywhere to impose cybersecurity duties across the entire lifecycle of products with digital elements. Details of the reporting duties are set out in the Commission’s Cyber Resilience Act reporting guidance.
Official reaction
“The Cyber Resilience Act ensures that digital products placed on the EU market are secure by design and that consumers can trust the connected devices they buy,” the European Commission said in its guidance on the regulation, stressing that obligations apply at every stage of the value chain.
Industry groups have broadly welcomed the security goal while warning that smaller manufacturers may struggle with the compliance paperwork. Legal advisers have urged firms to map their product portfolios now and identify which items fall under the law’s “important” or “critical” tiers, which carry stricter assessment rules.
Background
The EU Cyber Resilience Act was proposed by the Commission in September 2022 and entered into force in December 2024 after a surge in attacks exploiting poorly secured consumer and industrial devices. Lawmakers argued that the single market lacked any baseline security standard, meaning insecure products could circulate freely and be hijacked into botnets or used as entry points into critical networks. Full technical requirements can be found in the Commission’s Cyber Resilience Act policy pages.
With the September reporting deadline now weeks away, the coming months will test whether Europe’s ambitious cybersecurity rulebook can be enforced without overwhelming the manufacturers it is meant to discipline.




