The point: Starting in September 2024, the Cyber Resilience Act mandates the reporting of security vulnerabilities within 24 hours to authorities, requiring fundamentally changed incident response processes.
The EU regulation Cyber Resilience Act enters into force in September and introduces a 24-hour reporting obligation for discovered security vulnerabilities. Manufacturers and operators must report critical vulnerabilities to competent authorities significantly faster than has previously been customary.
The Cyber Resilience Act (CRA) requires manufacturers of hardware, software and IoT products to report vulnerabilities immediately starting in September. The deadline is a maximum of 24 hours after discovery. This applies to both known vulnerabilities and zero-days.
The regulation targets critical infrastructure and essential services – sectors such as energy, transport, health, telecommunications and finance. For CISOs this means concretely: internal processes for vulnerability detection and incident reporting must be designed for hours rather than days. At the same time, patches or workarounds must be provided or communicated more rapidly.
The 24-hour requirement differs significantly from previous standards such as those from NIST or European responsible disclosure practices, which typically provide 90 days. The aim of the EU regulation is to minimise response times to new threats and strengthen cyber resilience in critical sectors. At the same time, organisations must develop their documentation and audit trails sufficiently to demonstrate compliance.
Violations of the reporting obligation can result in substantial fines. CISOs should therefore review their vulnerability management workflows now, clarify communication channels with authorities and, if necessary, establish technical systems for real-time notification.
Source: news.google.com · Published 20 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.