The EU gave vendors 24 hours to report exploited flaws. Fines reach €15 million.
The reporting duties in Article 14 of the EU Cyber Resilience Act became mandatory on 11 September 2026, according to The Register.
A manufacturer has 24 hours after becoming aware of an actively exploited vulnerability to file an early warning. The detailed notification is due within 72 hours, followed by a final report 14 days after a fix is available. Severe incidents require a final report one month after the first.
The Register said filings go through ENISA, the European Union Agency for Cybersecurity's Single Reporting Platform, and the relevant national CSIRT.
The rule applies to manufacturers of products with digital elements sold in the EU, wherever they are based. The Register reported maximum fines of 15 million euros or 2.5% of annual turnover, whichever is higher.
Darren Anstee, chief technology officer at Netscout, said: "The 24-hour window...creates a level of urgency, with subsequent deadlines ensuring prompt information gathering."
If you place a product with digital elements on the EU market, your incident process now has a clock. It starts the moment someone in your company knows, not when they understand.
Who in your organisation can file that first 24-hour notice at two in the morning?
Sources
Every story here is open to read. The ERP LEADERS brief goes one step further.
One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.
Welcome back. · Issue 01
