EU Cyber Resilience Act to Enforce New Reporting Requirements

European Organizations Face New Reporting Obligations Under EU Cyber Resilience Act

As of this week, European organizations selling products in member countries will have to report product security issues quickly and diligently or face severe penalties. The EU’s Cyber Resilience Act (CRA) has introduced strict reporting obligations for organizations that distribute their products anywhere in the EU, with a focus on actively exploited vulnerabilities and severe security incidents.

The CRA is part of a larger regulatory framework aimed at enhancing cyber resilience across the European Union. While the full set of regulations won’t be enforced until December 2027, one key aspect has been fast-tracked to take effect immediately: the reporting requirement for serious product security issues. Organizations now have just 24 hours to notify the European Union Agency for Cybersecurity (ENISA) whenever they discover that a vulnerability or security incident is actively being exploited in their products.

If an organization fails to report such incidents within this timeframe, it could face fines of up to 15 million euros. These penalties are steep, but organizations have had time to prepare – the CRA has been under development for several years. The new reporting rules apply to both hardware and software products with network connectivity, regardless of whether the organization is physically based in the EU or not.

The scope of the regulations is broad, encompassing various aspects such as software bills of material (SBOMs), vulnerability handling processes, risk assessments, and more. Organizations must report any severe security intrusions that impact the availability, authenticity, integrity, or confidentiality of sensitive or important data or functionality. This could include supply chain breaches, for example.

Once a vendor has reason to believe an actively exploited vulnerability or severe security incident is occurring, they will need to flag it through ENISA’s Single Reporting Platform (SRP) within 24 hours. Within 72 hours, they must provide a more comprehensive notification, including information about the severity and impact of the issue at hand and mitigating steps users might take while waiting for a fix.

While microenterprises with fewer than 10 employees and small enterprises with fewer than 50 people are exempt from fines for missing their 24-hour windows, larger organizations will face no such exemptions. The EU has also announced that conformity assessments will be carried out in a proportionate manner when assigning financial penalties to smaller organizations.

In practice, this means that failing to report serious cybersecurity incidents could cost up to 15 million euros or 2.5% of an organization’s total worldwide annual revenue – whichever is greater. While the CRA’s reporting requirement and fines might be considered strict, it’s worth noting that the regulations also don’t enforce any reporting rule for known but not yet actively exploited vulnerabilities.

In conclusion, European organizations selling products in member countries must now take immediate action to report product security issues. To mitigate potential risks, it is essential for organizations to have a robust cybersecurity posture in place, including regular vulnerability assessments and incident response plans. By staying vigilant and proactive, organizations can minimize the impact of cyber incidents and avoid severe financial penalties under the EU’s Cyber Resilience Act.


Source: Dark Reading — 2026-09-10