Since 11 September 2026, manufacturers of products with digital elements have been required to report actively exploited vulnerabilities and severe incidents affecting the security of their products. This includes manufacturers of software and connected devices placed on the EU market, including products placed on the market before the Act's other requirements begin to apply.
The first step is to classify the event correctly: a vulnerability must be actively exploited, while an incident must meet the threshold of a severe impact on product security. An early warning must be submitted within 24 hours of becoming aware, followed by a fuller notification within 72 hours, through the single reporting platform operated by ENISA. A final report follows: for an actively exploited vulnerability, no later than 14 days after a corrective measure becomes available; for a severe incident, within one month of the 72-hour notification.
A company therefore needs a clear route from its technical team to the person responsible for reporting, a record of when it became aware of the event, and information about the affected product and measures taken. These reporting duties already apply. Most other Cyber Resilience Act requirements for digital products will apply from 11 December 2027. Companies should address the two dates separately in their compliance plans.