EU Digital Device Manufacturers Required to Report Cyber Attacks Within 24 Hours
The European Commission and the European Union Agency for Cybersecurity (ENISA) have announced that new rules requiring the reporting of cyber attacks and vulnerabilities came into effect in the European Union on Friday (11/9). This includes vulnerabilities that are being actively exploited by hackers in software and network-connected devices.
“Starting 11 September 202_ [Note: Source text says 2026, likely referring to the implementation timeline], manufacturers are required to report any actively exploited vulnerabilities as well as serious incidents that impact the security of their products. They must provide an initial warning within 24 hours, followed by a full notification within 72 hours,” the statement read.
These new requirements are mandated under the European Cyber Resilience Act (CRA) and apply to manufacturers of “products with digital elements,” which includes software and hardware that connect, directly or indirectly, to other devices or networks.
Alongside the implementation of these new requirements, the European Union also launched a dedicated Single Reporting Platform on 11 September. This platform allows manufacturers to report incidents to the relevant EU bodies and national computer incident response teams through a single notification.
Upon receiving a report, national authorities are required to forward it to the relevant bodies in other EU member states where the affected products are sold or used.
Although the Cyber Resilience Act begins to take effect in December 2024, its implementation is being carried out in stages. The obligation to report vulnerabilities and serious incidents is one of the first key requirements to be enforced.
Most provisions of the CRA will come into force on 11 December 2027. The legislation establishes uniform cybersecurity requirements for digital products across the entire EU market throughout the product’s lifecycle.