Editorial composite of network equipment connected by blue cables beside a separate European Union flag outside a modern building. Photos: Brett Sayles and aleksandre lomadze / Pexels. Representative equipment, not identified as compromised or endorsed by an EU institution.

EU cyber-reporting rules start September 11: what manufacturers must report

Written by Daniel Mercer

Published: 06:40, September 10, 2026

Manufacturers of connected hardware and software covered by the EU Cyber Resilience Act must begin reporting actively exploited security flaws and severe product-security incidents from September 11, 2026. The first warning can be due within 24 hours of becoming aware of a reportable event.

The deadline arrives tomorrow, but it is one stage of the law’s rollout. The European Commission’s implementation timetable puts the main product requirements, including broader design and maintenance obligations, on December 11, 2027.

For manufacturers, the immediate task is to make sure an urgent security finding reaches someone who can assess it and submit the required report. A technical team fixing the problem and a reporting team handling the notification may need to work at the same time.

Which businesses and products are covered?

The regulation generally covers hardware and software made available on the EU market whose intended or reasonably foreseeable use includes a connection to a device or network. Manufacturers outside the EU can also fall within its scope when supplying that market.

A connected router or a commercially supplied software product can be relevant examples. There are exclusions, including certain products covered by separate EU rules, so the law should not be treated as a reporting obligation for every business that uses a computer.

A manufacturer can be a company that has a product developed and sells it under its own name or trademark. It does not have to own a hardware factory. Ordinary business customers are not made manufacturers simply by buying and using that product.

A discovered bug is not always a reportable event

The Commission’s reporting guidance identifies two triggers: an actively exploited vulnerability in a covered product, or a severe incident affecting its security.

A vulnerability is a weakness that could be used to compromise security. “Actively exploited” means there is reliable evidence that a malicious actor has already used it in a system without the owner’s permission. A theoretical flaw found during routine testing does not automatically meet that threshold.

Severe incidents are a separate category. The legal criteria concern a product’s ability to protect important or sensitive data or functions, including circumstances involving malicious code. A company needs to assess the event against those criteria, rather than assuming every service interruption qualifies.

The reports arrive in stages

For a reportable event, manufacturers must send an early warning without undue delay and no later than 24 hours after becoming aware. A more detailed notification is due within 72 hours of awareness. The clock does not wait for the investigation or repair to finish.

Final-report deadlines differ. For an actively exploited vulnerability, the deadline is 14 days after a corrective or mitigating measure becomes available. For a severe incident, it is one month after the 72-hour notification.

Reports go through the Single Reporting Platform run by ENISA, the EU cybersecurity agency. Its frequently asked questions, updated on September 9, explain how manufacturers submit information to the relevant national computer-security response team and ENISA through one system.

Older products can still trigger a report

The reporting obligation also covers in-scope products placed on the market before December 2027. A manufacturer cannot assume that a product escapes the reporting rules because it was sold before the wider requirements take effect.

ENISA distinguishes this from retrospective reporting. A manufacturer does not have to report active exploitation it already knew about before September 11 solely because the new date arrives. Becoming aware after that date can trigger a report even where the underlying flaw is older.

Make the reporting route usable

The people submitting reports need personal EU Login accounts with multi-factor authentication, which adds an identity check beyond a password. ENISA says those accounts can be prepared in advance, while registration on the reporting platform is recommended when a notification is needed.

The platform will not offer an automated submission interface at launch. Manufacturers should therefore know who can submit a report manually and who will cover absences, as well as where product and incident information is kept.

For customers buying equipment, this is another reason to examine the supplier’s security-support arrangements. Our explainer on why businesses replace working equipment describes the operational problems that arise when updates end. Reporting a flaw gives authorities information; customers still need clear advice on patches, mitigations and continued use.

Daniel Mercer Avatar

Other News

Iridium shareholders approve Rocket Lab takeover: what still has to happen

Sep 25, 2026

Akamai’s 11.6 billion dollar Anthropic deal ties cloud revenue to a 5.5 billion dollar buildout

Sep 25, 2026

Bentley completes 350 million pound Crewe investment as it unveils its first electric vehicle

Sep 25, 2026

Falling birth rates did not reduce total output in historical data, NBER study finds

Sep 25, 2026

Cheaper renewable power does not solve the capital problem for poorer countries

Sep 25, 2026

Facial payments may feel novel, but money worries can curb repeat use

Sep 24, 2026

Precision farming cuts water use while raising crop yields, study finds

Sep 24, 2026

EU allocates €505m to Lebanon for recovery, reforms and basic services

Sep 23, 2026

Alcoa raises $2.6bn in notes to fund South32 aluminium-assets deal

Sep 23, 2026

UK workplace health plan targets preventable exits from employment

Sep 23, 2026

IMF says Sri Lanka’s recovery is holding, but the next review is still unresolved

Sep 23, 2026

OECD sees global growth holding up after energy shock, but forecasts higher inflation

Sep 23, 2026

QAD and Redzone plan NVIDIA-powered AI for factory data and production planning

Sep 22, 2026

World Cup pitchside sponsorship raised a cross-border advertising problem

Sep 22, 2026

Hollywood’s biggest budgets still favour male-only teams, study finds

Sep 22, 2026

Why more companies are becoming their own insurers

Sep 22, 2026

EU publishes data-centre rating rules and opens consultation on minimum standards

Sep 21, 2026

ABB launches Infinitus DC portfolio for AI data centers, with first full sites expected in two to three years

Sep 21, 2026

Starbucks selects Chennai for a technology hub, with work set to move in-house over time

Sep 21, 2026

CXMT says its G5 memory platform has entered mass production with more dies per wafer

Sep 21, 2026