Starting September 11, 2026, the Cyber Resilience Act (CRA), a key EU regulation (number 2024/2847), will require manufacturers of connected devices to report serious cybersecurity vulnerabilities and incidents. The CRA aims to establish a unified cybersecurity standard for digital products sold in the European Union, ensuring that devices are more secure and less prone to attacks. This regulation has been gradually introduced this year and includes strict reporting rules, with fines potentially reaching 15 million euros or 2.5% of a company's global annual revenue, whichever is higher. The CRA applies to a wide range of digital products, such as smartphones, routers, smart toys, and password managers, with varying requirements depending on how sensitive the product is. However, sectors already under other regulations—like medical devices, automotive, aviation, marine, and defense—are excluded.
The CRA’s implementation is happening in stages, from June 2026 to December 2027, giving companies time to adjust. On September 11, 2026, a new reporting system called the Single Reporting Platform will launch. Managed by ENISA, the European Union Agency for Cybersecurity, this platform will centralize all reports of exploited vulnerabilities or serious incidents. It will streamline the process by allowing national Cyber Security Incident Response Teams (CSIRTs) to share alerts with other countries while also informing ENISA. Both individuals and companies will be able to report issues through this centralized system.
Manufacturers and developers of open-source software used in digital products sold in the EU are required to report two types of events: vulnerabilities actively being used by attackers, and serious incidents that affect a product's availability, authenticity, integrity, or confidentiality. The reporting process is divided into three stages: a summary report within 24 hours, a more detailed analysis within 72 hours, and a final report 14 days after a fix is available for vulnerabilities, or one month after the 72-hour report for incidents. There are exceptions for specific cases outlined in the regulation.
To ensure compliance, manufacturers must undergo evaluations based on the sensitivity of their products. For less critical products, a self-assessment is enough. However, for high-risk items, independent checks by "notified bodies" are required. In France, ANSSI, the national cybersecurity agency, oversees these bodies, which must first be accredited by Cofrac. Post-market checks will be conducted by the National Frequency Agency (ANFR), with technical support from ANSSI, to ensure ongoing compliance. Companies that fail to follow the rules may face product recalls or hefty fines. The CRA works alongside other regulations like NIS2 and DORA to create a more complete cybersecurity framework across Europe.
European Cyber Resilience Act Enforcement Begins with New Reporting Requirements
AI-rewritten from original reportingHow it works
cybersecurityeu-regulationcravulnerability-reportingcompliance
Original sources:
- 🇫🇷Clubic



