Insight

The Cyber Resilience Act: vulnerability reporting from September 2026 and full obligations from December 2027

The Cyber Resilience Act sets cybersecurity requirements for hardware and software products with digital elements sold in the EU. Its reporting obligations for actively exploited vulnerabilities and severe incidents apply from 11 September 2026, while most other requirements apply from 11 December 2027.

Published by Somnium Digital

A wireframe of the Insight page: headline, supporting sections and a single call to action. Insight The Cyber Resilience Act Get in touch 01 What the Cyber Resili… 02 What is in scope 03 Reporting since 11 Se…

What the Cyber Resilience Act is

Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force on 10 December 2024. It introduces horizontal cybersecurity requirements for products with digital elements, meaning hardware and software products whose intended or reasonably foreseeable use includes a direct or indirect data connection to a device or network.

Where NIS2 regulates organisations that operate important services, the Cyber Resilience Act regulates products. It follows the logic of EU product legislation: manufacturers must meet essential requirements, carry out conformity assessment, draw up technical documentation and affix CE marking before placing products on the market.

Obligations apply in stages. Rules on conformity assessment bodies apply from 11 June 2026, reporting obligations from 11 September 2026, and the remaining obligations, including essential requirements and CE marking, from 11 December 2027.

What is in scope

The regulation covers a wide range of products, from connected consumer devices, routers and industrial controllers to desktop and mobile software, firmware and software components placed on the market separately. It covers remote data processing solutions that are necessary for a product to perform its functions, such as a cloud back end without which a connected device would not work.

Some products are excluded because other EU legislation already covers them, including medical devices, in vitro diagnostic devices, motor vehicles, certain aviation equipment and marine equipment, as well as products developed exclusively for national security or defence. Software as a service is generally outside scope unless it is a remote data processing solution for a product.

Free and open-source software developed or supplied outside the course of a commercial activity is not covered. The regulation introduces a lighter regime for open-source software stewards, organisations that systematically support open-source projects intended for commercial activities.

Reporting since 11 September 2026

Manufacturers must report actively exploited vulnerabilities contained in their products and severe incidents having an impact on the security of their products. Reports go simultaneously to the computer security incident response team designated as coordinator and to ENISA, through a single reporting platform.

The reporting obligations apply to all products with digital elements made available on the EU market, including products placed on the market before December 2027. That is why manufacturers need reporting processes now, even if their full conformity work is still planned for later.

Early warning
Without undue delay and in any event within 24 hours of becoming aware.
Notification
Within 72 hours, with general information about the vulnerability or incident, corrective or mitigating measures and an assessment of severity.
Final report for vulnerabilities
No later than 14 days after a corrective or mitigating measure is available.
Final report for severe incidents
Within one month after the incident notification.
Informing users
Manufacturers must also inform impacted users about the vulnerability or incident and any mitigation measures they can take.

Essential requirements from December 2027

From 11 December 2027, products must be designed, developed and produced to ensure an appropriate level of cybersecurity based on the risks. Requirements include delivering products without known exploitable vulnerabilities, secure default configurations, protection against unauthorised access, protection of the confidentiality and integrity of data, minimising attack surfaces and logging relevant security events.

Manufacturers must also handle vulnerabilities throughout a support period, which should reflect how long the product is expected to be in use and generally be at least five years unless the expected use time is shorter. They must provide security updates, maintain a coordinated vulnerability disclosure policy and a contact address for reports, and draw up a software bill of materials documenting at least the top-level dependencies.

Certain important and critical products listed in the regulation’s annexes, such as identity management systems, password managers, operating systems, routers and certain security products, face stricter conformity assessment procedures.

Importers, distributors and penalties

Importers and distributors must verify that products meet the requirements, including that the manufacturer has carried out conformity assessment and provides the required information, and must act when they become aware of vulnerabilities or non-conformity.

Market surveillance authorities enforce the regulation. Non-compliance with essential requirements and key manufacturer obligations can lead to administrative fines of up to 15 million euros or 2.5% of total worldwide annual turnover, whichever is higher.

What to do now

Start with an inventory of products, versions and components on the EU market, including embedded software and cloud services that products depend on. Establish how vulnerability reports are received, triaged and escalated, who decides whether a vulnerability is actively exploited, and how reports within 24 and 72 hours are prepared.

Build software bills of materials into development pipelines, define support periods and update processes, and review secure default settings. Companies that develop software or connected products for clients should clarify in contracts who is the manufacturer, who handles vulnerability reports and who provides updates.

Guidance and implementing acts continue to be published, so product teams should follow developments from the Commission and ENISA. This article is a general overview and not legal advice.

Questions

When did the Cyber Resilience Act enter into force?

On 10 December 2024.

What applies from 11 September 2026?

Manufacturers’ obligations to report actively exploited vulnerabilities and severe incidents affecting their products.

How fast must an actively exploited vulnerability be reported?

An early warning within 24 hours, a notification within 72 hours and a final report no later than 14 days after a fix or mitigation is available.

Do reporting duties apply to products already on the market?

Yes. They apply to products with digital elements made available on the market, including those placed before December 2027.

Does the regulation cover SaaS?

Generally not, unless the service is a remote data processing solution necessary for a product with digital elements to function.

How long must security updates be provided?

For a support period reflecting expected use, generally at least five years unless the product is expected to be used for less.

What are the maximum fines?

Up to 15 million euros or 2.5% of worldwide annual turnover, whichever is higher, for key breaches.

Where this sits in what we do

This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.

Shipping software or connected products in the EU?

We set up vulnerability intake and reporting workflows, software bills of materials in build pipelines and update processes that meet Cyber Resilience Act timelines.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp