EU Cyber Resilience Act to Enforce New Reporting Requirements

The European Union has taken a significant step towards enhancing cyber resilience in its member countries with the introduction of the Cyber Resilience Act (CRA). Starting September 11, businesses operating in the EU will be required to report serious product security incidents within 24 hours, or face hefty penalties. This move marks a major shift in the way companies handle cybersecurity issues and their impact on consumers.

The CRA is part of a larger set of regulations aimed at improving the security posture of organizations that sell products in EU member countries. The law requires companies to maintain detailed records of software components, vulnerability handling processes, and risk assessments – all of which will be strictly enforced by December 2027. However, one aspect of the regulation has been fast-tracked: the reporting obligation for actively exploited vulnerabilities or severe security incidents.

When a company discovers that its product is being exploited or compromised, it must notify the European Union Agency for Cybersecurity (ENISA) within 24 hours through their Single Reporting Platform (SRP). This notification must include basic information about the issue, such as its severity and impact. Within 72 hours, the company must provide a more comprehensive report, including mitigating steps users can take while waiting for a fix.

The EU has carved out an exemption for smaller organizations – those with fewer than 10 employees or less than €2 million in annual turnover. These companies will not be fined for missing their 24-hour window, although they may still face “proportionate” financial penalties if found to have failed to comply.

For larger organizations, the stakes are much higher. Failing to report serious cybersecurity incidents could cost up to €15 million or 2.5% of a company’s total worldwide annual revenue – whichever is greater. This highlights the significant emphasis placed on swift and accurate reporting under the CRA.

While some may argue that the CRA goes too far, others will see it as a necessary step towards enhancing cyber resilience in EU member countries. By requiring companies to report serious security incidents quickly, the EU hopes to reduce the impact of these incidents on consumers and businesses alike.

For companies operating in the EU, this new regulation presents both challenges and opportunities. On one hand, they must adapt their reporting processes to meet the 24-hour deadline and comply with strict penalties. On the other hand, it provides a chance for organizations to demonstrate their commitment to cybersecurity and build trust with consumers.

As the CRA takes effect, companies would do well to review their current reporting procedures and ensure that they are equipped to handle the new requirements. This includes developing robust vulnerability handling processes, maintaining accurate records of software components, and designating personnel responsible for reporting incidents within the 24-hour window. By taking proactive steps towards compliance, organizations can mitigate potential risks and avoid significant financial penalties.


Source: Dark Reading — 2026-09-10