EU's Cyber Resilience Act starts the 24-hour vulnerability clock
- ID
- 23538
- Status
- summarized
- Published
- 11 Sep 2026, 7:34 PM
- Fetched
- 11 Sep 2026, 11:31 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/5295821
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 6.5
- Created
- 11 Sep 2026, 11:33 PM
- Tags
- Audience
- developerssaas_founders
What happened
Article 14 of the EU's Cyber Resilience Act took effect on 11 Sep 2026, requiring manufacturers of products with digital elements sold in the EU to report actively exploited vulnerabilities within 24 hours via ENISA's Single Reporting Platform, with detailed notifications due in 72 hours and final reports within 14 days. The rules apply to non-EU manufacturers too, and require informing affected users of available corrections or mitigations.
Why it matters
If you ship any software, firmware, or connected hardware to EU customers—even from Malaysia—you now need a documented process to detect, triage, and report actively exploited vulnerabilities within 24 hours, or face non-compliance with the CRA. This means standing up incident-response runbooks and designating who files ENISA reports before a vulnerability forces an ad-hoc scramble.
Discussion angle
For founders and devs selling into the EU: do you have a 24-hour disclosure pipeline today, and what's the minimum viable incident-response process that satisfies CRA Article 14 without hiring a dedicated security team?