Jones Day·CYBERSECURITY

EU Cyber Resilience Act 24-Hour Reporting Starts September 11, 2026

Manufacturers of products with digital elements face binding 24-hour vulnerability and incident reporting to ENISA starting September 11, 2026, with fines up to €15M or 2.5% of global turnover.

The European Commission released 80+ pages of non-binding guidance on the Cyber Resilience Act on July 27, 2026, weeks before the regulation's reporting obligations take effect. Manufacturers must notify ENISA and the designated CSIRT through the Single Reporting Platform of any actively exploited vulnerability or severe incident affecting products with digital elements, including those placed on the market before December 11, 2027. The reporting clock starts when the manufacturer, after initial assessment, has reasonable degree of certainty of active exploitation or a severe incident. Timelines: 24-hour early warning, 72-hour notification, and a final report within 14 days (vulnerabilities) or one month (severe incidents). Manufacturers must also inform impacted users. Pre-September 11, 2026 known exploitations are excluded from retroactive reporting. Market surveillance authorities and notified bodies will rely on the guidance for consistent interpretation, making early alignment with its examples and flowcharts advisable.

cyber-resilience-actenisa-reportingvulnerability-disclosureeu-product-complianceincident-reporting-deadlines

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.