Daily Edition
Cyber Security · Tuesday, September 15, 2026 · 10 sources

EU mandates 24-hour cyber vulnerability reporting for digital products

Manufacturers of products with digital elements sold in the EU must now report actively exploited vulnerabilities and severe incidents within 24 hours via ENISA's new Single Reporting Platform. The obligations, which took effect on 11 September 2026, are the first phase of the Cyber Resilience Act, with fines of up to €15 million or 2.5% of global turnover for non-compliance.

Bottom line — Manufacturers selling digital products in the EU now face fines up to €15M for failing to report exploited vulnerabilities within 24 hours.

Go deeper (9)

  • ENISA launched the Single Reporting Platform on 11 September 2026, the same day the CRA reporting obligations took effect, per the agency.
  • Manufacturers must submit an early warning within 24 hours, a full notification within 72 hours, and a final report within 14 days for vulnerabilities or one month for severe incidents, the European Commission said.
  • The obligations apply to all products with digital elements made available in the EU, including those already on the market, per the Commission.
  • Crypto wallet makers are explicitly covered; open-source software stewards' reporting obligations begin on 11 December 2027, according to Crypto Briefing and Cointelegraph.
  • Fines for non-compliance with core obligations can reach €15 million or 2.5% of global annual turnover, whichever is higher, per the CRA text cited by Mondaq and Connect on Tech.
  • Micro and small enterprises are exempt from fines specifically for missing the 24-hour early warning deadline, Mondaq noted.
  • Louise Horton, government affairs lead at NCC Group, said the reporting requirements are 'the first real test of operational readiness' for many organisations, per Cybernews.
  • The platform allows manufacturers to file once and reach relevant national CSIRTs and ENISA simultaneously, according to Industrial Cyber.
  • The CRA's main cybersecurity requirements, including security-by-design mandates, apply from 11 December 2027, the Commission confirmed.

Read the reporting

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Sep 15, 11:30 AM UTC by wreetco wreetco

dstld. Your daily news summary designed to surface the news that matters from a European perspective. Curated by humans, summarized by AI - always with links back to the original reporting.

Links · Contact
Popular topics · WorldEuropeGamesAI
Last generated: Sep 15, 11:30 AM UTC by wreetco wreetco