Vilnius: In the Lithuanian capital, home to one of the Union’s most active cybersecurity communities, manufacturers of connected products are counting down to a deadline that will reshape how Europe handles digital vulnerabilities. The Cyber Resilience Act, the bloc’s first horizontal cybersecurity law for products with digital elements, brings its reporting obligations into force on 11 September 2026.
## A strict reporting clock
From that date, manufacturers must report actively exploited vulnerabilities and severe security incidents on a demanding timeline. An early warning is due within 24 hours of a company becoming aware of a problem, a fuller notification within 72 hours, and a final report once a fix is available. The requirement covers products already on the market, not only new releases, which dramatically widens its reach.
## The earlier June milestone
September is not the only date that matters this year. By 11 June 2026, member states had to designate the authorities responsible for assessing and notifying the conformity-assessment bodies that will eventually certify products. That administrative step is less visible than incident reporting, but without it the certification pipeline cannot function when the main obligations arrive in December 2027.
## Why the law was written
The rationale is straightforward. Insecure connected devices, from routers to industrial sensors, have become a systemic weakness, and the cost of breaches falls on users who had no way to judge a product’s security. By placing obligations on manufacturers across the entire lifecycle, the Act tries to shift responsibility toward those best placed to manage the risk.
## Industry’s concerns
Not everyone is reassured. Open-source maintainers worry about liability for freely shared code, and smaller manufacturers question whether they have the resources to meet the documentation and reporting burden. The Commission has sought to carve out genuine non-commercial open-source development, but the boundaries remain a live debate that compliance teams are watching closely.
## What happens next
With the September reporting deadline approaching, companies are racing to build vulnerability-handling processes and incident-response channels. The main body of obligations follows in December 2027, giving the market roughly a year and a half to prove that Europe can regulate product security without smothering the innovation it depends on. For consumers, the eventual promise is products that arrive secure by design and stay patched for a defined support period, ending an era in which a cheap connected gadget could quietly become an entry point for attackers long after purchase. Whether that promise is met will depend less on the legal text than on how rigorously national authorities enforce it once the certification system is fully running.




