Munich: For most of the digital age, a company that discovered its connected products were being actively attacked faced no firm legal duty to tell anyone quickly. That permissive era is ending. Under the European Union’s Cyber Resilience Act, the reporting obligations begin to bite from 11 September 2026, and from that date manufacturers of products with digital elements must move fast when something goes wrong.
The new regime is built around the clock. When a manufacturer learns that a vulnerability in its product is being actively exploited, or suffers a severe security incident, it must send an early warning within 24 hours. A fuller notification follows within 72 hours. For an exploited vulnerability, a final report is due 14 days after a patch becomes available; for a severe incident, the deadline stretches to one month. These are not gentle suggestions but defined obligations, and the tight intervals reflect a hard lesson from a decade of breaches: the gap between discovery and disclosure is the window in which attackers do their worst damage.
The reports flow to the European Union Agency for Cybersecurity, ENISA, and to national computer security incident response teams. ENISA is building the plumbing to receive them, a Single Reporting Platform meant to be operational by the September deadline, with a testing period beforehand so that companies are not improvising on the day the rules take effect. The platform is more than a mailbox. Pooling early signals about which products are under attack should let defenders across the Union see patterns that no single firm or country could spot alone, turning scattered incidents into actionable warning.
The Act phases in deliberately. Some provisions arrive ahead of the reporting duties: the rules on notifying conformity assessment bodies, the organisations that will certify whether products meet the Act’s security requirements, apply from 11 June 2026. The bulk of the substantive obligations, the design and lifecycle security duties that manufacturers must build into their products, do not take full effect until December 2027. ENISA is also being handed responsibility for cybersecurity certification schemes, framed as a practical and largely voluntary tool, where certification under a scheme grants a presumption that the relevant obligations have been met.
For industry, the shift is significant and not costless. The Act sweeps in an enormous range of products, from consumer gadgets to industrial components, and many manufacturers have never operated under anything resembling a 24-hour disclosure discipline. Building the internal machinery to detect, triage and report incidents at that speed demands investment, staff and a change of culture, and smaller firms in particular have warned about the burden. Supporters counter that the cost of insecurity has simply been externalised onto users for too long, and that a market flooded with poorly defended connected devices imposes its own steep price.
The deeper significance is what the Act says about responsibility. By making timely disclosure a legal duty rather than a public-relations choice, the Union is rebalancing the relationship between those who build digital products and those who depend on them. Whether the September machinery works as intended will become clear soon enough, when the first 24-hour warnings start arriving and the platform built to catch them is tested by real attacks rather than rehearsals.




