EU Cyber Resilience Act: Manufacturers face 24-hour deadline to report actively exploited vulnerabilities

September 18, 2026

EU CRA: 24-HOUR VULN REPORTING BEGINS

Manufacturers selling products with digital elements (PDEs) within the EU must now report actively exploited vulnerabilities within 24 hours of becoming aware of them.

The reporting obligations under the EU Cyber Resilience Act (CRA) started applying on 11 September 2026, ahead of most of the regulation’s other requirements, which will apply from 11 December 2027.

Following an early warning within 24 hours, manufacturers must submit a more detailed notification of actively exploited vulnerabilities within 72 hours of becoming aware of it. A final report must then be provided no later than 14 days after a corrective or mitigating measure becomes available.

Manufacturers must follow the same timetable for “severe” security incidents affecting PDEs, except the final report must be made within one month of the incident notification.

They must also inform impacted users – and, where appropriate, all users – about the vulnerability or incident and any necessary risk-mitigation measures.

PDEs encompass software or hardware products that connect to networks or other devices. That covers everything from smartphones, laptops and tablets to smart TVs, cameras and toys (with a few exemptions).

Depending on the provision breached, fines can reach €15 million or 2.5% of worldwide annual turnover (whichever is higher). Non-compliant products could also be restricted, withdrawn or recalled from the EU market.

Bug Bounty and the Cyber Resilience Act

The CRA explicitly references Bug Bounty as a vehicle for fulfilling coordinated vulnerability disclosure (CVD) obligations. Noting the widespread black-market sale of exploitable vulnerabilities in popular devices, the act says that PDE manufacturers “should be able to use programmes, as part of their coordinated vulnerability disclosure policies, to incentivise the reporting of vulnerabilities by ensuring that individuals or entities receive recognition and compensation for their efforts. This refers to so-called ‘bug bounty programmes’.”

The CRA also encourages EU member states to address the legal risks faced by good-faith security researchers, including by adopting guidelines on non-prosecution and exemptions from civil liability for their activities.

Other CRA security requirements

Manufacturers have until 11 December 2027 to prepare for the CRA’s wider cybersecurity requirements.

Vulnerability management- and offensive security-related provisions also include:

  1. Placing products on the market without known exploitable vulnerabilities
  2. Addressing and remediating vulnerabilities “without delay”
  3. Applying effective and regular tests and reviews of the security of their products
  4. Publicly disclosing information about fixed vulnerabilities, including their impact and severity and the availability of patches and mitigations
  5. Implementing coordinated vulnerability disclosure policies to facilitate external vulnerability reporting
  6. Distributing security updates securely, promptly and free of charge, accompanied by appropriate security advisories
  7. Producing a software bill of materials (SBOM) covering at least a product’s top-level dependencies

Testing ‘high-risk’ AI systems

Two years ago, when the CRA bill first emerged, is a lifetime ago in AI development, with the capabilities of the latest models increasing the need for continuous testing and smarter prioritisation, and sending cybersecurity shares soaring. However, the EU was a first mover when it comes to regulating the mitigation of AI risk. The CRA included requirements for “high-risk AI systems”, including accounting for “AI specific vulnerabilities such as data poisoning or adversarial attacks, as well as, as relevant, risks to fundamental rights”.

Support periods and other CRA requirements

From 11 December 2027, manufacturers must also handle vulnerabilities for a minimum support period of five years (unless the product’s lifetime expires sooner), with longer support periods for long-life components like microprocessors, network devices and operating systems. The CRA also introduces requirements related to authentication, encryption, minimising attack surfaces, reducing the impact of cyber-attacks and the collection of personal data.

The CRA forms a key plank of the EU’s wider efforts to strengthen its cybersecurity framework. Other notable pillars are Cybersecurity Act 2019 (introduced a common certification framework for ICT products), NIS 2 (Network and Information Security) Directive (wide-ranging requirements for member states and ‘essential’ or ‘important’ services) and the Digital Operational Resilience Act 2023 (ICT security rules for financial services firms). We examined the CRA’s offensive security-related provisions in greater detail in 2024.