CoinCustard editorial cover for tech beat story: EU Cyber Resilience Act 24-Hour Vulnerability Disclosure Goes Live Sept 11, 2026

EU Cyber Resilience Act 24-Hour Vulnerability Disclosure Goes Live Sept 11, 2026

EU Cyber Resilience Act 24-hour disclosure rules took effect across the European Union on September 11, 2026, starting a clock that security teams at every major connected-device maker had been watching for nearly two years. From this date forward, manufacturers that place products on the EU market must file an early warning with regulators within 24 hours of learning that a vulnerability in one of their products is being actively exploited, with a fuller technical notification due within 72 hours and a final post-incident report due within 14 days, extendable to 30 days for severe cases. Non-compliance carries fines of up to €15 million or 2.5% of global annual turnover, whichever is higher.

Why the EU Cyber Resilience Act 24-hour disclosure clock starts now

The 24-hour obligation is the operational core of a regulation that was years in the making but lands with very little grace period. September 11, 2026 is not a planning milestone; it is the first day on which missing a one-day reporting window can produce a financial penalty. The earlier 2026 milestone, June 11, was administrative: member states were required to designate the conformity assessment bodies that will evaluate products under Chapter IV of the law, and the EU cybersecurity agency ENISA began publishing the registration instructions and training materials that underpin the new reporting infrastructure.

Manufacturers now file through the CRA Single Reporting Platform (SRP), the ENISA-built portal that lets a company report once rather than to each of the bloc’s 27 member states. The architecture mirrors the logic of the General Data Protection Regulation: a single entry point backed by a competent authority network. For companies that already operate an internal product security incident response team, the SRP slot replaces a stack of national inboxes rather than building a new process from scratch. For everyone else, it forces one into existence.

What triggers the EU Cyber Resilience Act 24-hour disclosure clock

The distinction regulators drew between discovery and active exploitation is the one that will define the law’s day-to-day impact. The EU Cyber Resilience Act 24-hour disclosure obligation does not start when a bug lands in a tracker. It starts when a manufacturer becomes aware that a flaw in a product it has placed on the EU market is being used against real customers in the wild. A theoretical vulnerability does not start the timer; demonstrable exploitation does. That bar is higher than “report every bug,” but it is exactly the category of vulnerability that matters to the people who own the affected devices.

Once the timer starts, the multi-stage structure of the obligation is designed to push information upward quickly without demanding a finished forensic report on day one. The early warning is meant to be preliminary: a heads-up that something serious is happening, enough for authorities to issue coordinated guidance. The 72-hour notification adds the technical detail: the nature of the vulnerability or incident, the affected products, and any corrective or mitigating measures the manufacturer has taken or can make available. The final report, due within 14 days, is the post-mortem; for severe incidents it can extend to 30 days, on the assumption that a thorough accounting takes time but is still expected. ENISA’s SRP submission process is the practical mechanism through which all three stages are transmitted.

How a regional rule reshapes a global supply chain

The CRA’s reach is territorial in trigger and global in effect. The law applies to any device placed on the EU market regardless of where the manufacturer is headquartered. A product built in Shenzhen, designed in California, and sold in Berlin falls under the regulation because the customer is in Berlin. Manufacturers do not, as a rule, maintain separate product lines for separate markets when the same hardware can carry the same firmware, so the strictest applicable rule tends to become the default. That is the same extraterritorial logic that turned the GDPR into a global baseline, and it is the reason routers, smart speakers, and security cameras sold in North America, the Gulf, and East Asia will increasingly ship with EU-grade vulnerability-handling processes baked in.

The penalty structure reinforces that gravitational pull. Up to €15 million or 2.5% of global annual turnover for the preceding financial year, whichever is higher, is calibrated against the largest players in the market. For a small specialist vendor, the fixed figure can be the binding constraint. For a household-name consumer electronics maker, the percentage-of-turnover figure is the one that changes boardroom behavior; 2.5% of global revenue is not a rounding error for any company of scale, and boards have to weigh the cost of a missed one-day window against the cost of building the response capability that prevents one.

What consumers should look for next

For anyone buying connected devices, the law’s direct obligations land on manufacturers, not on end users. There is no new reporting duty in a living room. But the market signals that should follow are concrete and worth learning to read. A published security contact and a coordinated vulnerability disclosure policy are now baseline expectations under the CRA, not differentiators. A stated security update commitment for the device’s supported life is now a regulated promise rather than a marketing line. The absence of any documented vulnerability-handling process should be treated as the warning sign it has always been, with the new context that the absence will increasingly be the choice of a manufacturer that has decided not to meet its own legal minimum.

For the broader public, the second-order effect may matter more than the fines. The CRA creates a legal channel through which exploited vulnerabilities surface promptly and consistently, which should feed earlier and more reliable signals into the security research community, threat intelligence firms, and eventually consumers about which devices are under active attack. That kind of information flow is hard to value in advance, but it is the kind of structural change that, over an eighteen-month horizon, alters how confidently a household can plug a new piece of hardware into its network on the day it is unboxed. The headline number is the 24-hour clock; the deeper consequence is what flows through it, and the EU Cyber Resilience Act 24-hour disclosure regime that began on September 11, 2026.

Source: https://www.coincustard.com/tech/eu-cra-24-hour-disclosure-2026

Leave a Comment

Your email address will not be published. Required fields are marked *