EU Cyber Resilience Act to Enforce New Reporting Requirements
Recorded: Sept. 10, 2026, 7 a.m.
| Original | Summarized |
EU Cyber Resilience Act to Enforce New Reporting Rules Informa TechTarget|SearchSecurityCybersecurity DiveInformationWeekChannel DiveExplore our brandsAn Informa TechTarget PublicationDark Reading Resource LibraryBlack Hat NewsOmdia CybersecurityAdvertiseNewsletter Sign-UpNewsletter Sign-UpCybersecurity TopicsRelated TopicsApplication SecurityCybersecurity CareersCloud SecurityCyber RiskCyberattacks & Data BreachesCybersecurity AnalyticsCybersecurity OperationsData PrivacyEndpoint SecurityICS/OT SecurityIdentity & Access Mgmt SecurityInsider ThreatsIoTMobile SecurityPerimeterPhysical SecurityRemote WorkforceThreat IntelligenceVulnerabilities & ThreatsRecent in Cybersecurity TopicsApplication SecurityMythos Vulnerability Firehose Hits a Human BottleneckMythos Vulnerability Firehose Hits a Human BottleneckbyJai VijayanSep 9, 20264 Min ReadApplication SecurityUS Government Accuses Chinese AI Firms of Distilling Frontier ModelsUS Government Accuses Chinese AI Firms of Distilling Frontier ModelsbyAlexander CulafiSep 9, 20263 Min ReadWorld Related TopicsDR GlobalAsia PacificEuropeLatin AmericaMiddle East & AfricaSee AllThe EdgeDR TechnologyEventsRelated TopicsUpcoming EventsPodcastsWebinarsSEE ALLResourcesRelated TopicsResource LibraryWhite PapersReportsWebinarsNewslettersPodcastsHeard It From a CISOReporters' NotebookDark Reading's 20thVideosDark Reading PollsPartner PerspectivesMeet the EditorsAdvertise With Us About UsDark Reading Resource LibraryCybersecurity OperationsVulnerabilities & ThreatsCyber RiskApplication SecurityNewsBreaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.EU Cyber Resilience Act to Enforce New Reporting RequirementsStarting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.Nate Nelson,Contributing WriterSeptember 10, 20264 Min ReadSource: Alexey Krukovsky via Getty ImagesOrganizations that do business in the European Union (EU) will now have to report product security issues quickly and diligently or face steep penalties.The EU's Cyber Resilience Act (CRA) possesses a variety of regulations that won't be strictly enforced until December 2027. Organizations have plenty of time to make sure they meet the EU's requirements around, for example, software bills of material (SBOMs), vulnerability handling processes, risk assessments, and other aspects. However, as if to highlight its singular significance, the EU has fast-tracked a particular chunk of the CRA, so that it will come into effect more than a year before everything else.Beginning Sept. 11, all organizations that sell products in member countries will now be subject to strict reporting obligations. Namely, when they discover actively exploited vulnerabilities or severe security incidents affecting their products, they will have to report these issues to the European Union Agency for Cybersecurity (ENISA) within 24 hours. If they don't, they could face fines of up to 15 million euros.Related:Nigeria Looks to Sovereign Cloud for Cyber, National SecurityThe New Reporting Rules: What to KnowAs a rule, if an organization distributes its products anywhere in the EU, and if its products have any kind of network connectivity, then that organization is subject to the CRA. Hardware and software, for businesses and individuals, is all on the table. Only certain kinds of already EU-regulated technologies, and open source software, are out of scope. Companies do not need to be physically based in the EU to be subject to its laws.Beginning this week, organizations need to report actively exploited vulnerabilities in their products, and any other severe security intrusions that impact the availability, authenticity, integrity, or confidentiality of sensitive or important data or functionality. This latter example might include a supply chain breach, for instance.From the moment that vendors have some reasonable indication that one of these two events has occurred, they'll need to flag it through ENISA's Single Reporting Platform (SRP) within 24 hours. Within 72 hours — including, not in addition to, the first 24 — they'll have to provide a more comprehensive notification, including information about the severity and impact of the issue at hand and mitigating steps users might take while waiting for a fix.As soon as a fix is available, vendors will have a couple of weeks to submit a formal security report documenting it, and a month to file a more comprehensive, final report describing the whole picture to that point.Related:Europe's Multilingual Reality Exposes AI Security GapsThe EU did carve out an exemption to these deadlines only for the smallest of vendors. In consideration of their relatively lesser capabilities, microenterprises — those with fewer than 10 employees and less than 2 million euros in annual turnover — and small enterprises — fewer than 50 people, and 10 million euros — may not be fined for missing their 24-hour windows.So called "conformity assessments" will also be "carried out in a proportionate manner" when it comes to assigning financial penalties to micro-, small-, and medium-sized enterprises.Larger organizations will have no such exemptions. Failing to report serious cybersecurity incidents could cost up to 15 million euros, or 2.5% of a company's total worldwide annual revenue, if that number turns out to surpass 15 million.Does the CRA Get it Right?The near-instant reporting requirement and steep fines might be considered strict, but in other ways the CRA is rather lenient. Besides the exemptions for smaller organizations, it also doesn't enforce any reporting rule for known but not yet actively exploited vulnerabilities, no matter how severe they may be.It also allows for a bit of security by obscurity, where applicable. According to Article 16(2), "In exceptional circumstances and, in particular, upon request by the manufacturer and in light of the level of sensitivity of the notified information as indicated by the manufacturer under Article 14(2), point (a), of this Regulation, the dissemination of the notification may be delayed based on justified cybersecurity-related grounds for a period of time that is strictly necessary."Related:Is 'Tech-xit' Imminent? UK Steps Up Sovereignty Push Amid AI StrifeEven those fines aren't as scary as they seem, according to Dr. Aram Hovsepyan, CEO and founder of Codific and a founding board member of OWASP EU. "The maximum penalties are sending the right message," he says, "however, looking at the GDPR penalties given so far since 2018, it is obvious that the majority of fines were nowhere near the maximum amounts mentioned in the regulation."The bottom line, Hovsepyan says, is that organizations need to get incident detection and response right in order to comply with the CRA. The good news is that "Based on quantitative data from the OWASP SAMM Benchmarking project, we know that organizations are actually pretty good at those and especially when it comes to incident response. Especially in large organizations there are dedicated incident response teams in place. They are like professional firefighters, ready to jump in action with clear playbooks. Adding another compliance regulation to that playbook is straightforward at least from a process perspective," he says."Unfortunately, the reality gets complicated, as during a typical security incident organizations are more worried about their reputation than compliance," he adds. "How will their customers perceive the whole incident? How can they minimize the potential damage? That aspect is going to be more complex."Read more about:EuropeAbout the AuthorNate NelsonContributing WriterNate Nelson is a journalist and award-winning scriptwriter. In addition to Dark Reading he writes for Darknet Diaries, the most popular show in cybersecurity across all media.He began his career as a freelancer, ghostwriting Forbes and CNBC op-eds for executives in tech and finance. Then he transitioned to journalism at Threatpost, where he covered cybersecurity news and trends. Throughout those years he co-created a cybersecurity podcast, Malicious Life, which in its day climbed into the Top 20 technology podcasts charts on Apple Podcasts and Spotify.He holds degrees from New York University and Bard College. As a born and bred New Yorker, he enjoys a superiority complex, but is polite enough to keep it to himself.See more from Nate NelsonWant more Dark Reading stories in your Google search results?Add Us NowMore InsightsIndustry ReportsThe State of Cloud Security: The Latest ChallengesHow Organizations Are Managing Incident ResponseHow Enterprises Are Developing Secure ApplicationsInside RSAC 2026: security leaders reveal the risks redefining your defense strategyEssential News & Insights from Black Hat USA 2025Access More ResearchWebinarsCybersecurity Outlook 2027Threat Exposure Analytics: Measuring and Communicating Security RiskBenchmark Scores Are a False FlagBuilding an Effective Red Team: Beyond Penetration TestingHow to Leverage Threat Intelligence Without Drowning: The Zero Noise ApproachMore WebinarsFeaturedCheck out the Black Hat USA 2026 Conference Guide for coverage and intel from — and about — the show!Editor's ChoiceCyber RiskWhat We Missed: Delta Flight Disrupted With Wi-Fi HackWhat We Missed: Delta Flight Disrupted With Wi-Fi HackbyRob Wright,Alexander CulafiAug 20, 2026Cyberattacks & Data BreachesAgentic AI Presents New Insider Threat Model for OrgsAgentic AI Presents New Insider Threat Model for OrgsAug 19, 2026Want more Dark Reading stories in your Google search results?How Organizations Are Managing Incident ResponseNearly every organization faced a critical security incident last year, but most weren't equipped to contain it. Get the full findings in this free report.Download NowNovember 12, 2026 | VIRTUALWhat Every Enterprise Should Know About Securing Cloud Assets In the Age of AISave Your SpotKeep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.SubscribeDiscover MoreBlack HatOmdiaWorking With UsAbout UsMeet the EditorsAdvertiseReprintsJoin UsNewsletter Sign-UpFollow UsCopyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.Home|Cookie Policy|Privacy|Terms of UseYour Privacy Choices |
Organizations doing business within the European Union are now subject to strict reporting obligations under the Cyber Resilience Act (CRA), which mandates rapid disclosure of serious product security incidents. This legislation establishes various regulations that will be fully enforced by December 2027, providing entities ample time to prepare for compliance concerning areas such as software bills of materials, vulnerability handling processes, and risk assessments. Specifically, starting September 11th, any organization selling products in EU member states must report discoveries of actively exploited vulnerabilities or severe security incidents affecting their products to the European Union Agency for Cybersecurity (ENISA) within 24 hours. Failure to adhere to this timeline carries potential financial penalties of up to 15 million euros. The scope of the CRA applies broadly to organizations that distribute products across the EU, including both hardware and software, provided those products possess some form of network connectivity. The reporting requirements cover any security intrusions that impact the availability, authenticity, integrity, or confidentiality of sensitive or important data or functionality, which can encompass supply chain breaches. Vendors must flag such events through ENISA's Single Reporting Platform within the initial 24 hours. Following this initial report, vendors are required to provide a more comprehensive notification within 72 hours, detailing the severity and impact of the issue, as well as any mitigating steps users should take while awaiting a resolution. Furthermore, once a fix is released, vendors must submit a formal security report within two weeks, followed by a final, comprehensive report detailing the complete situation within one month. The reporting obligations are subject to some exemptions for smaller entities. Microenterprises, defined as those with fewer than ten employees and less than two million euros in annual turnover, and small enterprises, defined as those with fewer than fifty people and less than ten million euros in annual turnover, are exempt from these 24-hour reporting windows and associated fines. Conformity assessments for these smaller entities will also be managed in a proportionate manner. In contrast, larger organizations do not benefit from these exemptions. The potential penalties for non-compliance are severe, potentially reaching 2.5% of a company’s total worldwide annual revenue if the calculated fine exceeds fifteen million euros. Despite the stringent reporting requirements, the CRA incorporates some leniencies. For instance, reporting rules do not require notification for known vulnerabilities that have not yet been actively exploited, regardless of their severity. Additionally, Article 16(2) permits delays in disseminating notifications in exceptional circumstances, such as upon the manufacturer's request and based on the sensitivity of the information, provided justified cybersecurity grounds exist. Experts suggest that organizational success in complying with the CRA hinges significantly on robust incident detection and response capabilities. While the penalties are substantial, the actual fines imposed under previous regulations, such as GDPR, often did not reach the maximum amounts. Ultimately, organizations must focus on establishing effective incident response protocols, as ensuring regulatory compliance is intertwined with minimizing reputational damage following a security event. |