EU Cyber Resilience Act mandates 24-hour reporting for exploited software flaws starting September 2026
AI-generated from multiple sources. Verify before acting on this reporting.
BRUSSELS — Software vendors and manufacturers operating within the European Union must report actively exploited security vulnerabilities within 24 hours of discovery beginning September 11, 2026, under new enforcement measures from the EU Cyber Resilience Act. The regulation marks a significant shift in cybersecurity compliance, establishing strict legal obligations for digital product creators to maintain transparency and rapid response protocols.
The Cyber Resilience Act (CRA) introduces a comprehensive framework designed to enhance the security of products with digital elements throughout their lifecycle. Central to the new rules is the requirement for manufacturers to notify relevant authorities immediately upon identifying that a vulnerability is being actively exploited in the wild. This 24-hour window replaces previous voluntary or delayed reporting structures, aiming to mitigate the risk of widespread cyberattacks and data breaches across member states.
In addition to the accelerated reporting timeline, the act mandates that software vendors maintain accurate and up-to-date Software Bills of Materials (SBOMs). These detailed inventories must list all components and dependencies within a product, allowing regulators and users to trace potential risks through complex supply chains. The requirement ensures that if a specific component is compromised, affected products can be identified and patched without delay.
Regulators indicated that the September 11, 2026, deadline serves as the final implementation phase for these specific vulnerability reporting clauses. Manufacturers failing to comply with the 24-hour notification rule or those found maintaining inaccurate SBOMs face significant penalties, including fines and potential market withdrawal of non-compliant products. The measures are intended to level the playing field between established tech giants and smaller developers, ensuring uniform security standards across the single market.
The legislation comes as cyber threats targeting software supply chains have increased in frequency and sophistication. By enforcing strict disclosure timelines, the European Union aims to reduce the window of opportunity for malicious actors to leverage known flaws before patches are deployed. The act applies to any product with digital elements placed on the EU market, regardless of where the manufacturer is located.
Industry stakeholders are currently preparing internal workflows to meet the stringent new deadlines. While the framework provides clear guidelines on reporting mechanisms and SBOM standards, questions remain regarding the specific technical infrastructure regulators will use to monitor compliance in real-time. Additionally, the definition of "actively exploited" may require further clarification as vendors adapt their detection systems to distinguish between theoretical vulnerabilities and those under active attack. As the 2026 deadline approaches, the focus remains on whether global software ecosystems can align with these rigorous new European standards without disrupting critical digital services.