← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

EU Cyber Resilience Act's Vulnerability Reporting Requirements Take Effect September 2026

🔄 Updated 12h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • EU CRA vulnerability reporting starts September 11, 2026.
  • Companies must report actively exploited vulnerabilities within 24 hours.
  • Engineering requirements for product security apply from December 11, 2027.
  • The initial phase prioritizes reporting over mandated secure development practices.

Upcoming EU Cyber Resilience Act Requirements

The EU Cyber Resilience Act (CRA) introduces new obligations for manufacturers of products with digital elements sold within the European Union. These regulations are designed to enhance cybersecurity across the digital landscape by mandating specific actions from software vendors regarding vulnerability management and product security.

Phased Implementation of CRA

The CRA will be implemented in two distinct phases. The first phase, beginning September 11, 2026, focuses on vulnerability reporting. During this period, companies must notify ENISA within 24 hours of learning about an actively exploited vulnerability in their products, followed by a more comprehensive report within 72 hours. The second phase, starting December 11, 2027, will enforce engineering requirements, mandating how products are built and maintained to ensure inherent security.

The Initial Reporting Gap

The fifteen-month gap between the reporting obligation and the enforcement of engineering requirements means that companies will initially be required to disclose vulnerabilities without necessarily having fully implemented the CRA's secure development mandates. This period emphasizes visibility and rapid disclosure of exploited vulnerabilities, placing an immediate burden on companies to have robust internal processes for identifying and reporting security flaws.

Impact on Software Vendors

This phased approach means that companies must prepare their incident response and disclosure mechanisms well in advance of the engineering requirements. The initial focus on reporting exploited vulnerabilities highlights the need for effective security monitoring and a clear understanding of what constitutes an 'actively exploited' vulnerability, as well as the internal processes to meet the strict reporting timelines.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~8 min · 6 stories · Sep 08

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The EU Cyber Resilience Act (CRA) will require manufacturers selling products with digital elements into the EU to report actively exploited vulnerabilities within 24 hours of discovery, starting September 11, 2026. This initial phase focuses on visibility, preceding the December 2027 enforcement of engineering requirements for product security, creating a gap where companies must report issues before full compliance with building secure products is mandated.