Bottom line: The Cyber Resilience Act requires reporting of security incidents from 11 September onwards with penalties of up to €15 million for non-compliance.
As of 11 September 2024, the Cyber Resilience Act (CRA) reporting obligation enters into force. Organisations must report security incidents to authorities within defined time windows, or face fines of up to €15 million.
The Cyber Resilience Act comes into force on 11 September 2024 with its reporting obligations. Companies and organisations in the EU must report significant security incidents to the competent authorities from this date onwards.
The reporting obligation is staggered in time: authorities must be informed immediately, but no later than 24 hours after becoming aware of an incident. Affected individuals have a notification period of 72 hours. Anyone who fails to comply with these requirements risks fines of up to €15 million or 3 per cent of global annual turnover – whichever is higher.
CISOs must adapt their incident response processes and reporting channels accordingly. This particularly concerns the definition of “significant”, the documentation of detection times, coordination with authorities, and timely communication with affected persons. Organisations should also review their governance structures to ensure that compliance requirements are integrated into their existing security operations centres.
Source: news.google.com · Published 12 July 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.