A looming deadline for software vendors is about to turn an informal reality into a legal one. As of September 11, 2026, companies selling products with digital elements in the European Union will have to notify ENISA within 24 hours of learning that a vulnerability in their product is being actively exploited. A fuller report must follow within 72 hours. This new requirement stems from the EU Cyber Resilience Act (CRA), which aims to bolster cybersecurity across the continent.
For many companies, this isn’t a new challenge. Open source maintainers have long had to informally answer questions about what shipped and when they first knew there was a problem with it. But now, compliance teams will be held accountable for these answers, too. The law effectively becomes a visibility requirement until December 11, 2027, when more stringent engineering requirements kick in.
The gap between the current reporting deadline and the subsequent full notification clock is where manufacturers will face significant challenges. Not only do they need to quickly identify vulnerabilities, but also prove what shipped and when. This includes providing up-to-date software bills of materials (SBOMs), which can be a daunting task given the widespread use of open source components – 98% of applications contain them.
Industry statistics suggest that even identifying and remediating vulnerabilities is a time-consuming process: on average, it takes about 55 days to fix high or critical application vulnerabilities. This means manufacturers will have to navigate a tight deadline between early warning and full notification while simultaneously addressing the issue at hand. The EU CRA enforcement will live in this gap, with organizations caught in the middle.
The informal reality of open source maintainers has become an operational reality for the entire software world. With the EU Cyber Resilience Act now mandating how companies handle vulnerabilities, it’s essential to recognize that what shipped and when is a crucial question – one that needs to be answered accurately and promptly. Manufacturers must not only informally answer this question but also provide proof of their efforts.
In practical terms, manufacturers selling into the EU should start preparing for these new reporting obligations now. They need to develop robust processes for identifying vulnerabilities, updating SBOMs in real-time, and providing timely notifications. This includes investing in tools that can help track open source components and automatically update SBOMs as necessary. By doing so, companies can stay ahead of the regulatory curve and avoid potential fines or reputational damage.
Ultimately, the EU Cyber Resilience Act is a step towards greater transparency and accountability in software development. As manufacturers navigate this new landscape, they should view it as an opportunity to improve their processes and strengthen their cybersecurity posture – rather than just meeting compliance requirements.
Source: Bleeping Computer — 2026-09-08