Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

The EU gave vendors 24 hours to report exploited flaws. Fines reach €15 million.

The reporting duties in Article 14 of the EU Cyber Resilience Act became mandatory on 11 September 2026, according to The Register.

ERP LEADERS news desk · · First reported by The Register · Edition no. 5
Photo: EmDee/Wikimedia, CC BY-SA 4.0 · original

A manufacturer has 24 hours after becoming aware of an actively exploited vulnerability to file an early warning. The detailed notification is due within 72 hours, followed by a final report 14 days after a fix is available. Severe incidents require a final report one month after the first.

The Register said filings go through ENISA, the European Union Agency for Cybersecurity's Single Reporting Platform, and the relevant national CSIRT.

The rule applies to manufacturers of products with digital elements sold in the EU, wherever they are based. The Register reported maximum fines of 15 million euros or 2.5% of annual turnover, whichever is higher.

Darren Anstee, chief technology officer at Netscout, said: "The 24-hour window...creates a level of urgency, with subsequent deadlines ensuring prompt information gathering."

If you place a product with digital elements on the EU market, your incident process now has a clock. It starts the moment someone in your company knows, not when they understand.

Who in your organisation can file that first 24-hour notice at two in the morning?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story
ENISA

Every story here is open to read. The ERP LEADERS brief goes one step further.

One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01