EU CRA Starts the 24-Hour Reporting Clock

Article 14 of the EU Cyber Resilience Act became applicable today, putting manufacturers of products with digital elements sold in the EU on a 24-hour clock for early warning when they learn a vulnerability is actively exploited, with a fuller notification due within 72 hours. The same timetable applies to severe security incidents, and it reaches non-EU manufacturers too if they sell into the bloc. The reporting goes through ENISA’s Single Reporting Platform to the coordinating CSIRT, with a final report due later: 14 days after a corrective or mitigating measure is available for an exploited vulnerability, or one month after the first report for a serious incident. That turns disclosure into a regulated workflow, not just a security one, because the first filing may have to go out before internal triage is done. For product makers, the durable exposure is operational and legal: if the team cannot establish when it became aware of active exploitation, or cannot move that fact through security and compliance fast enough, the clock still runs. The law now makes rapid reporting part of vulnerability handling for any vendor with EU customers, not just EU-based companies.

Part of the PlainSec briefing for 2026-09-11

Editions

Sources