Skip to content

Cyber Resilience Act: Reporting Obligations Come Into Force in September 2026

The gist: The Cyber Resilience Act requires manufacturers to report security incidents within 24–72 hours starting September 2026, or face penalties up to 15 million euros.

Beginning 11 September 2026, the EU will introduce a phased reporting obligation for security incidents — three years before full implementation of the Cyber Resilience Act. CISOs must establish processes by then to avoid violations of the strict deadlines.

The Cyber Resilience Act (CRA) mandates reporting obligations starting 11 September 2026, although full implementation does not take effect until 11 December 2027. Manufacturers of digital products must then report actively exploited vulnerabilities and serious security incidents within defined timeframes: an early warning within 24 hours to the European Union Agency for Cybersecurity (ENISA) and the competent national computer emergency response team — in Germany, CERT-Bund — a detailed report within 72 hours, and a final report no later than 14 days after implementation of a remediation measure.

Violations of these deadlines incur substantial financial penalties: up to 15 million euros or 2.5 percent of worldwide annual turnover, whichever is higher. This makes the CRA one of the strictest compliance requirements that organisations must meet in the regulatory sphere to date.

According to analyses by security firm Cycode, many organisations exhibit significant preparation gaps: unclear responsibilities for escalating reports, unrealistic internal response times for detecting complex threats, missing product inventories including version information, and fragmented monitoring infrastructures with isolated security scanners. These deficiencies currently prevent the required deadlines from being met.

To comply with the requirements, organisations must establish comprehensive monitoring systems across the entire software development process: continuous monitoring of code bases, external dependencies, CI/CD environments, and AI components. In parallel, structured reporting processes, complete documentation, and regular crisis exercises under realistic conditions must be implemented. The combination of technical monitoring and clear escalation paths is necessary to reliably meet reporting deadlines.


Source: www.it-daily.net · Published 19 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: