Cybersecurity: EU Cyber Resilience Act Reporting Requirement in Effect
by
September 14, 2026
The EU Cyber Resilience Act’s reporting obligations went into effect on September 11, 2026. The intro to this Hunton memo provides an overview of the reporting requirements:
As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act (“CRA”). Products with digital elements include products that can be connected, directly or indirectly, to a device or network. This can include a wide range of connected consumer products and related apps.
The CRA entered into force on December 10, 2024. While the CRA’s main substantive obligations will apply from December 11, 2027, the incident reporting obligations take effect on September 11, 2026. Under such obligations, manufacturers are required to notify actively exploited vulnerabilities and severe incidents affecting the security of their products. This reporting obligation is one of the CRA’s first operational compliance requirements to take effect and is intended to support faster information sharing among relevant EU cybersecurity authorities.
Under the CRA, manufacturers that become aware of an actively exploited vulnerability or a severe incident with an impact on the security of a product with digital elements must follow a staged reporting process.
The memo reviews the applicable reporting timelines, outlines the mechanics of the reporting process, and discusses the limited mechanism provided under the CRA for delaying broader dissemination of the reported information to other EU regulators beyond the Computer Security Incident Response Team of the EU Member State to which the incident was reported.