EU Cyber Resilience Act Starts Its 24-Hour Vulnerability Clock in September
From 11 September 2026, manufacturers shipping connected products into the EU must report actively exploited vulnerabilities to ENISA within 24 hours, with penalties reaching 15 million euros.

The first hard deadline in the EU Cyber Resilience Act arrives on 11 September 2026. From that date, manufacturers of products with digital elements sold into the EU must report actively exploited vulnerabilities to ENISA and the relevant national CSIRT within 24 hours of detection. The regulation covers effectively anything that connects to a device or a network, which takes in IoT hardware, embedded systems, networking equipment and medical devices alike.
The scope is what catches teams out. This is not a rule for security vendors; it applies to any manufacturer placing a connected product on the EU market, including companies whose product happens to contain a network stack rather than being sold as a networking product.
Twenty-four hours is short enough that it cannot be met by improvisation. Meeting it requires knowing in advance who is on call, who is authorised to decide that an exploitation is active, and where the reporting channel is — decided before the first incident rather than during it. Full compliance with the rest of the act follows on 11 December 2027, which sounds distant but sits inside the design cycle of hardware being specified now.
Source: Tech Times