EU Cyber Resilience Act reporting: What CISOs need to know

The EU Cyber Resilience Act doesn't take full effect until 2027, but the mandatory vulnerability reporting deadline hits on September 11, 2026. Is your organization prepared?

Organizations selling digital products in the European Union face a key deadline: September 11, 2026. On this date, mandatory incident and vulnerability reporting begins under the EU's Cyber Resilience Act. Unprepared organizations could face financial penalties, as well as operational and market consequences, including product recalls, market bans and personal liability.

Key dates

The Cyber Resilience Act entered into force on December 10, 2024, and will be fully applicable on December 11, 2027.

Chapter IV, which went into effect on June 11, 2026, marked the legal start of designating conformity assessment bodies -- third-party organizations that assess whether products comply with the Cyber Resilience Act -- and the beginning of their operations.

September 11, 2026, marks a key milestone: Manufacturers -- including OEMs and open source software stewards -- will be required to follow reporting guidelines for actively exploited vulnerabilities and severe incidents.

  • Actively exploited vulnerabilities are security flaws that threat actors have used in a real-world attack. They exclude routine bugs, ordinary patches or vulnerabilities patched before exploitation.
  • Severe incidents include events that compromise sensitive data or involve the introduction or execution of malicious code in a product.

The European Commission published guidance supporting the implementation of the Cyber Resilience Act in July, noting that "the structure of the reporting obligations requires manufacturers to update their notifications progressively, as their internal investigations advance and their knowledge of the actively exploited vulnerability or incident becomes more detailed."

As of September 11, manufacturers must report vulnerabilities and incidents to the EU Agency for Cybersecurity (ENISA) and their designated EU Computer Security Incident Response Team (CSIRT) following this timeline:

  • Within 24 hours. Submit an initial early warning upon becoming aware of an exploited vulnerability. Include information such as whether the event might be malicious.
  • Within 72 hours. Provide more detailed information, including an initial assessment of the incident's severity, the nature of the vulnerability, any mitigation steps taken by the organization and recommended actions for users.
  • Within 14 days for an actively exploited vulnerability or a month for a severe security incident. Submit a comprehensive final report detailing the vulnerability, exploit characteristics and corrective actions taken, including the formal corrective or mitigating measure, such as a patch.

These reporting requirements have retroactive implications.

"It doesn't matter if the product shipped in 2019. If it's still in use and contains an actively exploited vulnerability, it must be reported," according to Sai Honig, senior advisor at cybersecurity consultancy Novera. This applies to all products with digital elements -- any product with a data connection to a device or network -- placed on the market before December 11, 2027.

The Cyber Resilience Act also advises manufacturers to inform users about severe incidents and provide corrective measures to mitigate their impact.

Noncompliance with the reporting requirements is subject to administrative fines of up to €15 million or up to 2.5% of the organization's total worldwide annual turnover for the preceding financial year, whichever is higher.

Understanding the Cyber Resilience Act

This regulation represents a shift in cybersecurity accountability. The EU identified "a structural market risk," according to Biljana Cerin, team lead, information security management at IT services company Jungheinrich Croatia.

"Manufacturers could sell connected products without being consistently accountable for cybersecurity over the lifetime of their products," she explained.

To manage this risk, the act sets clear and mandatory cybersecurity requirements across the full lifecycle of digital products and requires that manufacturers design, update and maintain devices and software to protect users.

The act essentially shifts cybersecurity accountability risk from consumers to manufacturers, targeting a core problem across hardware and software. "Most connected products that have historically reached the EU market arrived with little to no baked-in security," Honig said. "The costs of those gaps fell on consumers and businesses rather than manufacturers."

Preparing for compliance: What CISOs need to do

Despite the approaching deadline, many organizations remain unprepared. A survey by ENISA found that 66% of respondents from small to medium-sized enterprises had heard of the Cyber Resilience Act, highlighting a gap between awareness and practical readiness. In fact, one in five survey participants said they weren't sure whether the Cyber Resilience Act even applied to their organization.

CISOs and cybersecurity leaders, especially those working at manufacturers, should take the following steps to prepare for the mandatory reporting:

  • Assess scope. Create an inventory of all Cyber Resilience Act-relevant products, including legacy ones still in use.
  • Map legal responsibility. Identify the legal entities responsible for meeting Cyber Resilience Act obligations. This is particularly important for group structures, co-development models, OEM and white-label arrangements, products distributed through multiple entities and products containing third-party components.
  • Strengthen vulnerability management. Implement coordinated disclosure processes for intake, triage, remediation, notification workflows and evidence retention.
  • Create software bills of materials. Machine-readable SBOMs become mandatory on December 11, 2027. "If you don't have SBOMs in place, you cannot comply," Honig said. "SBOM readiness needs to be treated as mandatory well ahead of the official Cyber Resilience Act SBOM deadline."
  • Test incident response plans and processes. Prepare documentation for self-assessment or third-party audits, run tabletop incident response simulations that include ENISA reporting steps and fix any identified gaps. For example, run a tabletop exercise that assumes an actively exploited vulnerability is discovered at 4 p.m. on a Friday. Find out whether the organization could produce a regulator-ready notification by 4 p.m. on Saturday, Cerin suggested. "If the answer is no, then the organization is not yet ready for the reality of the Cyber Resilience Act."
  • Prepare for platform integration. ENISA's single reporting platform will be available on September 11, 2026. CISOs and their teams should test internal submission workflows and incorporate them into incident response playbooks.

While much of the conversation around the Cyber Resilience Act centers on reporting deadlines, Cerin said, reporting is only the final step in the process.

"What organizations need to ask themselves is whether they can identify, assess and escalate an actively exploited vulnerability quickly enough to meet those deadlines," she said. "That is where the real challenge begins."

Samira Sarraf is an award-winning international business and technology journalist and editor with 15 years of experience. She has published news and features on CSO Online, CIO.com, Computerworld, ARNnet, TechPartner News and more.