US Edition
Your source for latest news
TechnologyCybersecurity Regulation

EU's 24-Hour Hack-Reporting Rule Takes Effect, Reaching Far Beyond Europe

A new EU law now requires makers of software and connected devices to report actively exploited flaws within 24 hours, or face fines of up to €15 million — a deadline that lands on U.S. and Asian vendors as squarely as European ones.

PT
By PressTemps Technology DeskPublished Today, 09:25 ET · 6 min read
EU's 24-Hour Hack-Reporting Rule Takes Effect, Reaching Far Beyond Europe
The Berlaymont building in Brussels, headquarters of the European Commission, which oversees the Cyber Resilience Act's implementation. Photo: Euro Pictures / S'ARTIST PHOTOGRAPHY / Wikimedia Commons, CC BY 2.0
What to know
The EU's Cyber Resilience Act now requires manufacturers of connected products sold in the bloc to report actively exploited vulnerabilities within 24 hours, with fuller notifications due at 72 hours and final reports at 14 to 30 days.
The obligation, under Article 14 of Regulation (EU) 2024/2847, took effect September 11, 2026, 15 months before the law's broader product-security requirements arrive in December 2027.
Non-compliance carries fines up to €15 million or 2.5 percent of a company's global annual turnover, whichever is greater, and the rule applies to any manufacturer selling into the EU regardless of where it is based.
ENISA's Single Reporting Platform, the portal for these filings, launched the same day the duty took effect, after industry trackers flagged in June that the system was not yet operational.

A new legal clock started ticking across the European Union on Friday. As of September 11, 2026, any company that sells software, industrial controllers, smart-home devices or other "products with digital elements" into the EU market must report actively exploited security vulnerabilities to regulators within 24 hours of becoming aware of them. The obligation, set out in Article 14 of the Cyber Resilience Act, is the first enforceable piece of a sweeping EU cybersecurity law that otherwise does not fully apply until December 2027.

The EU's cybersecurity agency, ENISA, brought online the system built to receive those reports on the same day the duty took effect. In an announcement posted Friday, the agency said it had deployed the "initial operating capability" of its Single Reporting Platform, the portal manufacturers and open-source software stewards must now use to notify authorities of exploited flaws and severe incidents affecting products sold in the bloc.

What the rule requires

The Cyber Resilience Act, formally Regulation (EU) 2024/2847, does not require every bug or routine patch to be reported. Two narrower categories trigger the duty, according to the European Commission's own summary of the reporting obligations: a vulnerability for which there is reliable evidence of active, malicious exploitation, or a "severe incident" that damages the availability, authenticity, integrity or confidentiality of a product or the data and services connected to it.

Once a manufacturer becomes aware of either, the clock has three checkpoints. An early-warning notice, containing basic details such as the manufacturer and product name, is due within 24 hours. A fuller notification describing the nature of the exploit and any mitigations is due within 72 hours. A final report — covering root cause, severity and the remedy applied — is due within 14 days of a fix becoming available for a vulnerability, or within one month for a severe incident. Reports go through the Single Reporting Platform to the national computer security incident response team, or CSIRT, tied to the company's main EU establishment, which then shares the notification with ENISA and with CSIRTs in every other member state where the product is sold.

Companies that miss the deadlines, submit false information, or ignore the duty altogether face fines of up to €15 million or 2.5 percent of a firm's total worldwide annual turnover, whichever figure is larger — a penalty structure modeled on the EU's General Data Protection Regulation.

A law with global reach

The Cyber Resilience Act does not distinguish between European and foreign companies. Any manufacturer that places a connected product on the EU market — a cloud-based enterprise application built in California, a networking appliance made in Taiwan, an industrial sensor assembled in Ohio — falls within scope if that product reaches EU customers. Legal and compliance advisories tracking the law have stressed that the obligations attach to products already on shelves and in deployment, not only to new releases, meaning vendors cannot simply wait out older product lines. Open-source software stewards, such as foundations that maintain widely used code libraries, are also covered by Article 14, though their own reporting duties were left with a longer runway to December 2027, per the Commission's guidance.

That breadth is what has drawn the most attention from security and legal teams outside Europe in the run-up to Friday's deadline. Coverage of the rule's launch by Tech Times noted that the reporting duty arrives 15 months ahead of the law's broader product-security requirements, making it, in effect, the Cyber Resilience Act's opening test of how seriously global vendors intend to comply — well before the harder requirements around secure-by-design engineering, software bills of materials and CE marking arrive at the end of 2027.

Readiness concerns going into launch day

The rule's start date and the reporting platform's launch date were, by design, the same day — a compression that drew criticism from compliance specialists in the weeks before Friday. An analysis published by the industry tracking site cyberresilienceact.eu found that as of late June the platform was not yet operational, leaving manufacturers well under three months to prepare processes, identify their responsible CSIRT and train staff once training materials appeared. The same analysis noted the version of the platform going live Friday would exclude some planned features, including voluntary reporting and an application programming interface for automated submissions, meaning some companies would initially file manually.

ENISA's own messaging framed Friday's launch as a milestone rather than a finished product. The agency said it had published a user manual, tutorial video, glossary and multilingual factsheets alongside a dedicated help desk to support manufacturers navigating the new obligations, and described the rollout as supporting "a more coordinated EU approach to the reporting and handling of cybersecurity risks."

Who is affected, and what officials are saying

The immediate audience for the new duty is corporate: security, legal and compliance teams at any company that sells a connected product into 27 EU member states, from major cloud and software vendors to smaller industrial-equipment makers and IoT manufacturers. Downstream, the law is intended to benefit the operators of hospitals, power grids, transit systems and telecommunications networks that rely on those products, by giving national authorities faster, standardized visibility into flaws being actively exploited against them, rather than learning of them piecemeal or after public disclosure.

ENISA's executive director, Juhan Lepassaar, framed the platform's purpose in those terms in the agency's launch announcement.

"Vulnerabilities in digital products are often exploited by threat actors to subvert or hamper critical services, such as healthcare, energy, transport or telecommunications. The streamlined reporting and sharing of information on actively exploited vulnerabilities and severe incidents helps to build a more resilient Digital Single Market."

Legal advisories aimed at multinational manufacturers have made a parallel point from industry's side: that the reporting duty will now sit alongside other EU incident-reporting regimes, including the NIS2 directive for critical infrastructure operators and DORA for financial-sector technology, creating overlapping notification windows that in-house teams will need to reconcile rather than treat as separate obligations.

What happens next

For now, enforcement will center on whether companies actually use the Single Reporting Platform as exploited flaws surface in the coming weeks — the first real test of a system that went live on the same day it became mandatory. ENISA has signaled it plans to build out the platform's missing pieces, including the reporting API and a field to record exactly when a company first became aware of an issue, over the following months. The Cyber Resilience Act's full regime — secure-by-design requirements, mandatory software bills of materials and CE-marking conformity assessments for digital products — remains on track for December 11, 2027, the date by which the law's transition period formally ends.

Until then, September 11 stands as the moment the EU's cybersecurity rulebook stopped being a future deadline for global technology vendors and became a live legal obligation, with a 24-hour countdown attached.

More on this story

All Technology