CYBER WIRE
What Day is Today in Cyber?

EU Cyber Resilience Act: 37 Days to the Reporting Duty

On the CISO triangle · Process

Live  days left today · CRA reporting duty · 11 Sep 2026

Nothing in cyber regulation actually lands today. 5 August is a quiet date. But a clock is running underneath it.

37 days until EU Cyber Resilience Act reporting begins

That's how long product teams have until the EU Cyber Resilience Act (CRA) reporting obligations start on 11 September 2026.

From that date, manufacturers of Products with Digital Elements (PDEs) will face new operational reporting duties:

  • 24 hours for initial notification of actively exploited vulnerabilities. [the clock starts the moment you are "aware". Somebody now has to define that word.]
  • 72 hours for vulnerability notification through the EU Single Reporting Platform. (one platform that learns about your unpatched flaws before your customers do)

The obligation applies not only to products launched after the deadline, but also to products that have already been placed on the market. [including the one whose maintainer left in 2023]

For product security teams

The Cyber Resilience Act changes vulnerability management from an internal security process into a regulated reporting activity. [which makes a missed deadline a legal event]

Organizations need clear ownership, escalation paths, vulnerability triage processes, and communication procedures before the reporting clock starts. [ownership is the hard one. The rest is documentation.]

← All dispatches