Skip to content
Tech

Since 11 September, EU software makers must give a 24-hour warning of exploited flaws

Since 11 September 2026, makers of connected software and hardware sold in the EU must report actively exploited flaws, starting with an early warning due within 24 hours. Fines can reach €15 million.

Open-plan coworking office with people working at glass-walled desks and chatting in a lounge with colorful paintings on the walls
Open-floor plan coworking office space in Technology Hub's business center facility in Ciudad Juarez, Mexico.Missionedit · CC BY-SA 4.0 · via Wikimedia Commons

The EU Cyber Resilience Act sets cybersecurity rules for products with digital elements made available on the EU market. Its duty to report security problems began on 11 September 2026. The Irish National Cyber Security Centre describes those products as including software as well as hardware.

For a founder, the practical questions are which events must be reported, how quickly, and what a missed deadline can cost. The sources below answer those questions and flag where they are silent or disagree.

Which dates have already passed

The regulation entered into force on 10 December 2024, according to the National Cyber Security Centre.

Its reporting obligations, set out in Article 14, took effect on 11 September 2026. The Commission says the reporting platform has been operational since that date.

Matheson says the CRA becomes fully applicable on 11 December 2027, and the NCSC gives December 2027 for full technical product compliance. The Commission ties 11 December 2027 to reporting duties for open-source software stewards, a separate group. Matheson says non-compliant products cannot be lawfully placed on the EU market after that date.

Products placed on the market before December 2027 are exempt from design rules, according to the NCSC, but remain subject to reporting if they are still available in the EU.

What must be reported

Manufacturers must report two kinds of event. The first is a vulnerability under active exploitation. The second is a severe incident that affects the security of a product with digital elements. The Commission's reporting page uses these two categories.

The NCSC describes an actively exploited vulnerability as a flaw where reliable evidence shows a malicious actor is actively exploiting the vulnerability in the wild.

Matheson describes a severe incident as one that negatively affects, or could negatively affect, a product's ability to protect the availability, authenticity, integrity or confidentiality of data or functions. The NCSC page describes reportable events in similar terms, covering product security functions, data confidentiality and system integrity.

Matheson defines a product with digital elements as any software or hardware product, and its remote data processing solutions, that connects directly or indirectly to a network. The NCSC gives a shorter description: any hardware or software that connects directly or indirectly to a network. Its examples include laptops, smart devices, operating systems, mobile apps and industrial IoT.

For third-party components, manufacturers must report once they confirm their product is affected, according to the NCSC.

The reporting clock: 24 hours, 72 hours and final reports

The reporting clock is already running, and it begins when a company becomes aware of the problem. Matheson measures both the early warning and the notification from awareness.

The first report is an early warning, due within 24 hours of awareness. The NCSC says it should be submitted without waiting for a deep technical analysis. Matheson describes it as due without undue delay and within that 24-hour window.

The next stage is a fuller notification. Matheson gives 72 hours from awareness, unless the information has already been provided. The NCSC describes this stage as due within 48 hours of the early warning submission, which is 72 hours from initial awareness. It includes an initial severity assessment, root cause and temporary mitigations. Both sources give the same overall limit.

Final reports run on separate timelines. For actively exploited vulnerabilities, the final report is due no later than 14 days after a corrective or mitigating measure is available. For severe incidents, it is due within one month after the vulnerability notification is submitted. The NCSC says the final report includes a full root-cause analysis and corrective actions.

Microenterprises and small enterprises are exempt from fines for missing the 24-hour early warning deadline, according to Matheson's summary. The sources read for this article do not set out the size thresholds.

One platform, one report

Manufacturers report once, through the CRA Single Reporting Platform. Under Article 16, ENISA, the EU cybersecurity agency, set up the platform in close cooperation with the CSIRT Network. The Commission says the platform has been operational since 11 September 2026.

The notification goes to the CSIRT in the country where the manufacturer has its main establishment. Unless exceptional circumstances apply, ENISA receives the information at the same time. That CSIRT then shares it without delay with the CSIRTs in every territory where the product is made available.

The Commission's page says a CSIRT may delay that sharing in exceptional cases, on justified cybersecurity grounds. A delegated act adopted on 11 December 2025 sets out the terms and conditions for such delays.

Only submissions through the platform satisfy the statutory obligations, according to the NCSC. Email to the NCSC fallback address is for voluntary alerting, and is accepted only if ENISA officially declares the platform offline. Once the platform is available, official notifications must be submitted through it.

Matheson adds that if a manufacturer does not promptly inform impacted users, the CSIRT notifies them instead.

“The reporting clock is already running, and it begins when a company becomes aware of the problem.”

What a missed deadline can cost

Matheson reports that breaches of the vulnerability and incident reporting duties fall under Tier 1, with fines of up to €15 million or 2.5% of global annual turnover, whichever is higher.

Matheson's summary sets lower ceilings for other categories. It gives fines of up to €10 million or 2% for other obligations, and up to €5 million or 1% for providing incorrect, incomplete or misleading information. Matheson's summary describes Tier 2 as covering importer and distributor duties and failure to cooperate with market surveillance authorities.

The Commission's reporting page does not mention penalties, and the NCSC page gives no penalty figures. The fine ceilings in this article therefore come from Matheson's summary.

Matheson also says open-source software stewards are excluded from the fines regime. It also describes two manufacturer duties: support for at least five years, or the product's expected lifespan if shorter, and technical documentation kept for at least ten years.

Where the scope is still unsettled for software companies

The NCSC says manufacturers must carry out their own legal and technical assessment to decide whether a product qualifies for an exemption. It mentions exemptions for offline products and strictly excluded sectors but does not list them.

The NCSC page does not address importers or distributors. Matheson's summary refers to importer and distributor duties under Tier 2.

The definition of a product with digital elements includes remote data processing solutions, but the sources read do not say how the rules apply to software delivered as a hosted service. The sources do not settle that question.

The reporting duties are already in force. None of the pages read describe the internal process a company needs to detect and assess events, so this article does not describe one. The Commission page points to section 9.1 of its guidance for reporting obligations.

Related