Tallinn: The smart doorbell, the factory sensor and the home router share a problem that their makers have rarely been forced to confront in public: when a flaw in their software is being actively exploited, no one is obliged to say so quickly. The Union’s cybersecurity rules for connected products are about to change that, and the first hard deadline arrives in September, when manufacturers must begin reporting actively exploited vulnerabilities and serious incidents through a single, centralised channel.
The obligation is the opening phase of a broader law governing products with digital elements, legislation that will eventually require almost anything sold with software inside it to meet baseline security standards across its lifetime. The reporting duty comes first because regulators regard early warning as the cheapest defence available. A vulnerability that one company knows about but keeps quiet is a vulnerability that attackers can ride across thousands of other devices before anyone organises a response.
The mechanics are demanding. Once a manufacturer becomes aware that a flaw is being exploited, it must file an early warning within twenty-four hours, a fuller notification within seventy-two, and a final report once a fix is available. The notifications run through a new single reporting platform that the Union’s cybersecurity agency is tasked with building and running, a system meant to route each disclosure to the appropriate national incident-response team while giving the agency a simultaneous view. The platform is supposed to be operational by the same September date, which leaves little margin for delay.
For companies, the compliance burden is real and unfamiliar. Firms that have never had a formal vulnerability-disclosure process must now build one capable of meeting a twenty-four-hour clock, with the legal and reputational stakes that attach to a regulated filing. Smaller manufacturers, in particular, worry about the resources required to monitor their products closely enough to know when an exploit is under way, and about the liability that flows from getting the judgement wrong. Industry groups have asked for clarity on exactly what counts as an actively exploited vulnerability, a definition that will shape how often the obligation bites.
Security researchers, by contrast, see the rules as overdue. The market for connected devices has long rewarded speed and price over durability, and products have routinely shipped with known weaknesses that were never patched because no one was accountable for them. A mandatory reporting regime, backed by an agency that aggregates the data, could finally give defenders a real-time picture of which products are under attack and force manufacturers to treat security as a continuing responsibility rather than a one-off feature.
The unresolved questions are about capacity. Building a platform that can absorb a continent’s worth of incident reports, protect the sensitive information they contain and feed it usefully to dozens of national teams is a formidable engineering task on a fixed schedule. So is preparing thousands of companies, many of them outside the traditional technology sector, to meet a deadline they may only dimly understand. The law’s logic is sound, but its first test will be operational, and it lands in a matter of months whether or not everyone is ready.




