Particle.news

EU Cyber Resilience Act Reporting Rules Take Effect

New short reporting deadlines now require manufacturers to move fast to find, assess and report exploited vulnerabilities.

Overview

  • The CRA's initial reporting duties, which began on 11 September 2026, require manufacturers to send a 24-hour early alert and a 72-hour follow-up then submit final reports within set windows for vulnerabilities and serious incidents.
  • ENISA's Single Reporting Platform went live on the same day and routes submissions to national authorities such as Germany’s BSI for handling and coordination.
  • A representative Bitkom survey of 1,003 German companies found 67% had heard of the CRA but only 29% understood what it means for their business, indicating a wide awareness but practical comprehension gap.
  • Industry experts warn many firms lack the basic data and processes needed to comply quickly, specifically inventories, Software Bills of Materials (SBOMs), and formal vulnerability-handling and update-mapping procedures, and they could not preregister or rehearse the new platform before launch.
  • With full product-conformity rules phasing in for items placed on the EU market from 11 December 2027, regulators will likely watch early reporting performance closely and companies must test workflows now to avoid fines, supply disruptions or consumer risk.