The EU Cyber Resilience Act (CRA) introduces new obligations for manufacturers of products with digital elements sold within the European Union. These regulations are designed to enhance cybersecurity across the digital landscape by mandating specific actions from software vendors regarding vulnerability management and product security.
The CRA will be implemented in two distinct phases. The first phase, beginning September 11, 2026, focuses on vulnerability reporting. During this period, companies must notify ENISA within 24 hours of learning about an actively exploited vulnerability in their products, followed by a more comprehensive report within 72 hours. The second phase, starting December 11, 2027, will enforce engineering requirements, mandating how products are built and maintained to ensure inherent security.
The fifteen-month gap between the reporting obligation and the enforcement of engineering requirements means that companies will initially be required to disclose vulnerabilities without necessarily having fully implemented the CRA's secure development mandates. This period emphasizes visibility and rapid disclosure of exploited vulnerabilities, placing an immediate burden on companies to have robust internal processes for identifying and reporting security flaws.
This phased approach means that companies must prepare their incident response and disclosure mechanisms well in advance of the engineering requirements. The initial focus on reporting exploited vulnerabilities highlights the need for effective security monitoring and a clear understanding of what constitutes an 'actively exploited' vulnerability, as well as the internal processes to meet the strict reporting timelines.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
The EU Cyber Resilience Act (CRA) will require manufacturers selling products with digital elements into the EU to report actively exploited vulnerabilities within 24 hours of discovery, starting September 11, 2026. This initial phase focuses on visibility, preceding the December 2027 enforcement of engineering requirements for product security, creating a gap where companies must report issues before full compliance with building secure products is mandated.