The EU’s Cyber Resilience Act is moving from legislation to implementation, with manufacturers facing their first major compliance deadline next month.

The EU’s Cyber Resilience Act is moving from legislation to implementation, with manufacturers facing their first major compliance deadline next month.
From 11 September 2026, manufacturers of products with digital elements will be required to report actively exploited vulnerabilities and severe security incidents.
The requirement covers a broad range of connected hardware and software sold in the EU, as the bloc moves towards making cybersecurity a requirement throughout the lifecycle of digital products.
Under the new reporting obligations, manufacturers must issue an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident, followed by a more detailed notification within 72 hours.
Reports will be submitted through a Single Reporting Platform operated by the EU Agency for Cybersecurity, ENISA. The platform is due to become operational alongside the reporting requirements on 11 September.
The deadline marks the first significant application of the Cyber Resilience Act, which entered into force in December 2024. Its broader requirements, including mandatory cybersecurity measures covering the design, development and maintenance of products, will apply from December 2027.
Ahead of the September deadline, the European Commission published new practical guidance on 27 July to help manufacturers and developers understand how the rules will work in practice.
The guidance clarifies issues including which products fall within the CRA, what constitutes a substantial modification to an existing product, how manufacturers should determine support periods and how the reporting and cybersecurity risk assessment requirements should be approached.
The distinction between a vulnerability and an actively exploited vulnerability will be particularly important. The September rules do not mean that every newly discovered flaw must be reported. Reporting is triggered where there is reliable evidence that a malicious actor has exploited a vulnerability affecting the product, or where an incident has had a severe impact on its security.
That places greater importance on the processes surrounding vulnerability disclosure and incident response. Manufacturers will need to be able to determine quickly whether an issue meets the CRA threshold, establish when they became aware of it and ensure the relevant teams can meet the 24 and 72-hour reporting windows.
The CRA is ultimately intended to shift more responsibility for cybersecurity towards the companies that develop and sell digital products. September’s reporting deadline will provide an early indication of how that principle works in practice, well before the Act becomes fully applicable in December 2027.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543