Editorial composite of network equipment connected by blue cables beside a separate European Union flag outside a modern building. Photos: Brett Sayles and aleksandre lomadze / Pexels. Representative equipment, not identified as compromised or endorsed by an EU institution.

EU cyber-reporting rules start September 11: what manufacturers must report

Written by Daniel Mercer

Published: 06:40, September 10, 2026

Manufacturers of connected hardware and software covered by the EU Cyber Resilience Act must begin reporting actively exploited security flaws and severe product-security incidents from September 11, 2026. The first warning can be due within 24 hours of becoming aware of a reportable event.

The deadline arrives tomorrow, but it is one stage of the law’s rollout. The European Commission’s implementation timetable puts the main product requirements, including broader design and maintenance obligations, on December 11, 2027.

For manufacturers, the immediate task is to make sure an urgent security finding reaches someone who can assess it and submit the required report. A technical team fixing the problem and a reporting team handling the notification may need to work at the same time.

Which businesses and products are covered?

The regulation generally covers hardware and software made available on the EU market whose intended or reasonably foreseeable use includes a connection to a device or network. Manufacturers outside the EU can also fall within its scope when supplying that market.

A connected router or a commercially supplied software product can be relevant examples. There are exclusions, including certain products covered by separate EU rules, so the law should not be treated as a reporting obligation for every business that uses a computer.

A manufacturer can be a company that has a product developed and sells it under its own name or trademark. It does not have to own a hardware factory. Ordinary business customers are not made manufacturers simply by buying and using that product.

A discovered bug is not always a reportable event

The Commission’s reporting guidance identifies two triggers: an actively exploited vulnerability in a covered product, or a severe incident affecting its security.

A vulnerability is a weakness that could be used to compromise security. “Actively exploited” means there is reliable evidence that a malicious actor has already used it in a system without the owner’s permission. A theoretical flaw found during routine testing does not automatically meet that threshold.

Severe incidents are a separate category. The legal criteria concern a product’s ability to protect important or sensitive data or functions, including circumstances involving malicious code. A company needs to assess the event against those criteria, rather than assuming every service interruption qualifies.

The reports arrive in stages

For a reportable event, manufacturers must send an early warning without undue delay and no later than 24 hours after becoming aware. A more detailed notification is due within 72 hours of awareness. The clock does not wait for the investigation or repair to finish.

Final-report deadlines differ. For an actively exploited vulnerability, the deadline is 14 days after a corrective or mitigating measure becomes available. For a severe incident, it is one month after the 72-hour notification.

Reports go through the Single Reporting Platform run by ENISA, the EU cybersecurity agency. Its frequently asked questions, updated on September 9, explain how manufacturers submit information to the relevant national computer-security response team and ENISA through one system.

Older products can still trigger a report

The reporting obligation also covers in-scope products placed on the market before December 2027. A manufacturer cannot assume that a product escapes the reporting rules because it was sold before the wider requirements take effect.

ENISA distinguishes this from retrospective reporting. A manufacturer does not have to report active exploitation it already knew about before September 11 solely because the new date arrives. Becoming aware after that date can trigger a report even where the underlying flaw is older.

Make the reporting route usable

The people submitting reports need personal EU Login accounts with multi-factor authentication, which adds an identity check beyond a password. ENISA says those accounts can be prepared in advance, while registration on the reporting platform is recommended when a notification is needed.

The platform will not offer an automated submission interface at launch. Manufacturers should therefore know who can submit a report manually and who will cover absences, as well as where product and incident information is kept.

For customers buying equipment, this is another reason to examine the supplier’s security-support arrangements. Our explainer on why businesses replace working equipment describes the operational problems that arise when updates end. Reporting a flaw gives authorities information; customers still need clear advice on patches, mitigations and continued use.

Daniel Mercer Avatar

Other News