The European Commission has announced the start of new reporting obligations under the Cyber Resilience Act (CRA), aimed at improving the cybersecurity of digital products across the EU. From 11 September 2026, manufacturers must rapidly report actively exploited vulnerabilities and serious security incidents affecting products with digital elements, ranging from smart home devices and wearables to software applications.
Under the new rules, companies must issue an early warning within 24 hours of discovering a threat, provide a full notification within 72 hours, and submit a final report once corrective measures are available. The reporting requirements apply to all digital products sold in the EU and will be managed through the CRA Single Reporting Platform operated by the European Union Agency for Cybersecurity (ENISA).
According to the European Commission, the measures will help consumers receive faster alerts and better protection against cyberattacks affecting connected devices. The CRA forms part of the EU’s broader cybersecurity strategy, with its main product security requirements taking effect on 11 December 2027.