As of 11 September 2026, companies that make software and connected devices for the European market have a new legal clock to watch. Under the EU’s Cyber Resilience Act (CRA), manufacturers must now report actively exploited vulnerabilities and severe incidents to the authorities, starting with an early warning within 24 hours. The European Union Agency for Cybersecurity, ENISA, opened the platform for those reports on the same day.
What happened
The Cyber Resilience Act is the EU law that sets security requirements for “products with digital elements”, a broad term that covers software and hardware sold in EU markets. Most of the law comes into force later, but one part has now started. According to the European Commission, manufacturer reporting obligations “commence 11 September 2026”.
The Commission sets out a staged timeline for each report:
- an early warning within “24 hours”
- a fuller notification within “72 hours”
- a final report no later than “14 days” after a corrective measure is available, for vulnerabilities
- a final report within “one month”, for severe incidents
All of these notifications go through “the CRA Single Reporting Platform (SRP)”, which ENISA runs. ENISA launched the initial operating capability of that platform on 11 September 2026.
ENISA’s Executive Director, Juhan Lepassaar, framed the reason plainly: “Vulnerabilities in digital products are often exploited by threat actors to subvert or hamper critical services”.
Who is affected
The obligation falls on manufacturers of products with digital elements that are sold in the EU. That includes companies outside Europe. If you are building an app, a connected device or a piece of software in Riyadh, Cairo or Dubai and selling it to European customers, this applies to you.
Open-source software stewards, the organisations that support open-source projects, get more time. Their reporting obligations begin on 11 December 2027, according to the European Commission.
It is important not to overstate what has changed. This is the reporting duty, not the whole law. The full set of CRA obligations applies later, in December 2027. What starts now is the requirement to tell the authorities, quickly, when something is being exploited.
For ordinary users, there is nothing to do. The benefit, in my view, should be faster warnings about flaws in products we already own.
By the numbers
| Item | Detail | Source |
|---|---|---|
| Manufacturer reporting starts | 11 September 2026 | European Commission |
| Open-source steward reporting starts | 11 December 2027 | European Commission |
| Early warning deadline | 24 hours | European Commission |
| Full notification deadline | 72 hours | European Commission |
| Final report, vulnerabilities | No later than 14 days after a corrective measure is available | European Commission |
| Final report, severe incidents | One month | European Commission |
| Reporting channel | CRA Single Reporting Platform (SRP) | European Commission |
| Platform operator | ENISA | European Commission, ENISA |
| SRP initial operating capability | 11 September 2026 | ENISA |
What to do now
These steps are for software and device makers, and they follow guidance from ENISA and the European Commission.
- Register on the CRA Single Reporting Platform and name a person who owns the 24-hour early warning. A deadline that short needs someone who knows it is theirs, including at weekends.
- Set up a clear vulnerability disclosure contact and an intake process, so that reports from researchers and customers reach the right team quickly.
- Map which of your products count as “products with digital elements” and which of them are sold in EU markets.
- Use ENISA’s FAQs, manuals and help desk when you are unsure how a case should be reported.
For a small startup, I would start with step 1. Many young teams have a good product and a weak on-call process, and 24 hours passes very quickly when nobody is sure who should act.
Why it matters
Arab tech companies are increasingly selling abroad, and Europe is a natural market for many of them. Until now, how quickly a maker disclosed an exploited flaw was largely up to the maker. From this week, for products sold in the EU, it is a legal deadline measured in hours.
I like the shape of the timeline. The 24-hour warning is short on purpose. It asks for a signal first and details later, which is realistic, because nobody fully understands an incident in its first day.
I think this will spread beyond Europe in practice. Once a company builds a 24-hour reporting habit for its EU customers, it rarely makes sense to run a slower process for everyone else. That could mean faster security warnings for users in our region too, even though the law itself is European.
Sources
- ENISA, “The CRA Single Reporting Platform is launched”, 11 September 2026, https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched
- European Commission, Cyber Resilience Act reporting obligations, 2026, https://digital-strategy.ec.europa.eu/en/policies/cra-reporting