From the journal

EU Cyber Resilience Act Reporting Obligations Take Effect 11 September 2026

The EU Cyber Resilience Act's incident and vulnerability reporting requirements take effect on 11 September 2026, more than fourteen months before the Act's full compliance date of December 2027. Manufacturers of products with digital elements placed on the EU market must notify national CSIRTs and ENISA of actively exploited vulnerabilities within 24 hours and of severe security incidents within 72 hours, with a final report due no later than 14 days after a corrective measure is available.

2 min read

The reporting requirements under the Cyber Resilience Act (Regulation (EU) 2024/2847, 'CRA') take effect on 11 September 2026. This date is the first of the CRA's three phased deadlines, preceding the general compliance date of 11 December 2027 by more than fourteen months. The reporting obligations also apply to products with digital elements placed on the EU market before the CRA's full compliance date, provided those products remain on the market.

Article 14 CRA obliges manufacturers of products with digital elements to notify the designated national Computer Security Incident Response Team (CSIRT) and ENISA of any actively exploited vulnerability in their product and of any severe incident affecting product security. A preliminary notification is due within 24 hours of the manufacturer becoming aware of the event. A follow-up notification must be submitted within 72 hours. A final report is due no later than 14 days after a corrective measure is available for actively exploited vulnerabilities, or within one month for severe incidents.

Manufacturers placing products with digital elements on the EU market bear the reporting duty directly, with no exception for company size or sector. Affected entities include software publishers, IoT device makers, cloud service component providers, and any other entity whose product contains digital elements and is placed on the EU internal market. National market surveillance authorities hold enforcement powers under the CRA's penalty provisions.

ENISA launched the Single Reporting Platform on 11 September 2026 to receive mandatory notifications. ENISA is a coordination and collection point, not a supervisory authority for enforcement purposes. Products placed on the EU market before 11 December 2027 are also subject to the September 2026 reporting requirements if they remain on the market at that date.

Licentium and its partner network advise manufacturers and importers on CRA readiness. Work we undertake includes product compliance reviews, notification procedure design, CSIRT coordination support, and EU regulatory filing assistance.

Source: Cyber Resilience Act - Reporting Obligations, European Commission Digital Strategy, 11 September 2026

More from the journal

See all

Dutch DPA Fines Uber €824.99 Million for GDPR Article 22 Violation, August 2026

On 21 August 2026, the Autoriteit Persoonsgegevens imposed a fine of €824,990,000 on Uber B.V. for fully automated deactivation of drivers' accounts in breach of GDPR Article 22, which prohibits automated individual decision-making that produces legal or similarly significant effects on data subjects without a qualifying exception. The penalty is the second largest GDPR fine on record, behind the €1.2 billion fine imposed on Meta by the Irish DPA in 2023.

European Commission Designates ChatGPT a Very Large Online Search Engine Under DSA

On 31 August 2026, the European Commission designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act. OpenAI reported 159.1 million average monthly active recipients in the EU for the six months ending 31 March 2026, exceeding the 45 million designation threshold by more than three times. Designated services must meet enhanced DSA obligations within four months of notification.

MAS Consults on Legislative Implementation of Singapore Stablecoin Regime, 1 September 2026

On 1 September 2026, the Monetary Authority of Singapore published a consultation paper setting out draft amendments to the Payment Services Act 2019 to convert its 2023 stablecoin policy into enforceable statute. Key proposals require 100% reserve backing in high-quality liquid assets, prohibit interest payments on MAS-regulated stablecoins, and restrict the 'MAS-regulated stablecoin' label to licensed issuers only. The consultation closes on 16 October 2026.