European manufacturers of connected and digital products face new mandatory cybersecurity reporting duties from 11 September as the EU’s Cyber Resilience Act moves from legislative preparation into operational compliance.
The European Union Agency for Cybersecurity, ENISA, is bringing its Cyber Resilience Act Single Reporting Platform into operation to receive notifications of actively exploited vulnerabilities and severe security incidents involving products with digital elements.
The platform is intended to replace multiple notifications with a central submission process. Manufacturers select the relevant national Computer Security Incident Response Team, or CSIRT, when filing, while ENISA manages the platform and dissemination arrangements operate under the Cyber Resilience Act.
The reporting timetable is demanding. Manufacturers must issue an early warning without undue delay and, in any event, within 24 hours of becoming aware of an actively exploited vulnerability or severe incident.
A fuller notification is required within 72 hours. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective measure such as a patch becomes available. For a severe incident, the final report is due within one month of the 72-hour notification.
At launch, the platform supports mandatory reporting of actively exploited vulnerabilities and severe incidents. Voluntary reporting functionality has not yet been implemented.
The change creates an operational requirement reaching beyond security teams. Meeting a 24-hour early-warning deadline requires companies to establish escalation routes capable of identifying an event, deciding whether it meets the statutory threshold, locating the relevant EU reporting authority, and assembling information quickly enough to file.
Multinational manufacturers also need internal coordination. ENISA states that only one notification is required for any individual vulnerability or severe incident even where a manufacturer has multiple branches or subsidiaries in the EU.
Responsibility for coordinating that submission therefore has to be clear before an incident occurs. Uncertainty over which subsidiary, legal team, security function, or assigned representative owns the process could consume a large part of the reporting window.
The regime pushes cybersecurity compliance further into the product lifecycle. Companies selling connected hardware and software can no longer treat vulnerability management solely as a technical remediation exercise; exploitation can now trigger regulatory deadlines alongside engineering, customer communications, legal review, and incident containment.
Third-party software creates another complication. Modern products frequently depend on libraries, embedded software, cloud services, and components supplied by other organisations. Manufacturers need sufficient visibility over those dependencies to determine quickly whether a newly exploited weakness affects products for which they remain responsible.
Software inventories, coordinated vulnerability-disclosure processes, and defined ownership between engineering and compliance teams therefore become more important as the reporting regime begins.
The platform does not initially provide an application programming interface. Companies can automate their internal reporting workflows and data preparation, but mandatory notifications must be submitted through the platform interface at launch.
ENISA has published supporting material including FAQs, a glossary, and guidance for assigned representatives. It has also warned that some deadline counters within the initial release are reference tools and do not replace the manufacturer’s responsibility to calculate and meet the statutory reporting period correctly.
The new duties are among the first Cyber Resilience Act obligations to affect manufacturers directly. Wider product-security requirements will follow, but incident and exploited-vulnerability reporting is already live from 11 September.
Manufacturers selling products with digital elements across the EU now need reporting procedures capable of recognising a qualifying event, coordinating internally, and meeting the new 24-hour and 72-hour deadlines while remediation work is still under way.




You must be logged in to post a comment.