Tallinn: A cyber resilience deadline is bearing down on every company that sells software or connected gadgets into Europe, and the clock now shows weeks rather than years. From 11 September, manufacturers must report actively exploited vulnerabilities and severe security incidents under the European Union’s Cyber Resilience Act.
The regulation covers products with digital elements, a category that stretches from smart doorbells and routers to industrial control software. Companies will file an early warning within twenty-four hours of learning that attackers are abusing a flaw, a fuller notification within seventy-two hours, and a final report once they ship a fix.
Firms send those reports through a single platform that routes them to national response teams and to ENISA, the bloc’s cybersecurity agency. The Commission built the one-stop channel so that a vendor selling across the Union no longer files the same alert twenty-seven times.
The reporting duty arrives well before the rest of the law. Manufacturers face full compliance only on 11 December 2027, when the broader security-by-design obligations take hold. Rules for the bodies that certify products already applied in June, part of a staggered timetable meant to soften the shock.
Industry groups broadly back the goal yet warn about the pace. Smaller developers say the tight windows will strain teams that lack a dedicated security desk, and they worry that a rushed early warning could tip off other attackers. The Commission counters that speed protects users and that reports stay confidential until a patch lands.
The obligations reach backward as well as forward. Legacy products already on the market fall inside the net, so a vendor cannot dodge the rules simply because a device shipped before the law took hold. That sweep worries makers of long-lived hardware that receives few updates.
Regulators see the reporting regime as an early-warning radar for the whole continent. By funnelling exploited flaws into one database, they hope to spot attack campaigns sooner and warn other firms before the damage spreads. The Commission’s guidance spells out the thresholds.
For software makers, the message is blunt. The paperwork of a breach is no longer optional, and the first missed deadline could draw a regulator’s eye long before the heavier 2027 duties arrive. Companies that map their reporting chain now will spend September fixing bugs rather than hiring lawyers. National authorities, for their part, will judge firms less on the odd flaw than on how honestly and quickly they own up to it.




