Compliance dates · 11 September 2026 · EU
Cyber Resilience Act reporting starts on 11 September 2026 with a 24 hour clock
From 11 September 2026 the Cyber Resilience Act reporting regime runs. An actively exploited vulnerability or a severe incident in a product with digital elements carries a 24 hour early warning to ENISA and to the national CSIRT.
The clock is the hard part. Twenty-four hours is short enough that the reporting route has to exist before the first report is needed, not be assembled once something has gone wrong. ENISA and the national CSIRT are both named, so the early warning runs to two destinations rather than one.
Manufacturers of products with digital elements
Any manufacturer placing hardware or software with digital elements on the EU market, including small software vendors. Placing the product on the EU market is the test, not where the manufacturer sits.
Standing up a reporting route
- List the hardware and software with digital elements you place on the EU market.
- Identify your national CSIRT and the ENISA route the early warning goes through.
- Name the person who files the 24 hour early warning and the person who covers for them.
- Write down what counts internally as an actively exploited vulnerability or a severe incident.
- Rehearse the 24 hour path once before 11 September 2026.
The Cyber Resilience Act system
Reporting is one duty inside the Cyber Resilience Act, and the system covers the Regulation whole.
Cyber Resilience Act £1,500
Security requirements for products with digital elements placed on the EU market.
Regulation (EU) 2024/2847 · European Union
Verified 19 August 2026.