In just 20 days, manufacturers face EU’s new vulnerability reporting mandates

Effective worldwide and starting September 11, 2026, all manufacturers of goods shipped into the EU must notify The European Union Agency for Cybersecurity (ENISA) within 24 hours of any actively exploited vulnerability. 

Most have focused on the EU Cyber Resilience Act‘s (CRA) ultimate December 2027 deadline, but as of this Friday, 20 days away, manufacturers become newly accountable for digital resilience throughout the entire product lifecycle. 

  • Within 24 hours of discovering any actively exploited vulnerability, they must notify ENISA and a designated Computer Incident Response Team (CSIRT).
  • Within 72 hours, they owe a detailed follow-up notification, including a description of corrective action.
  • Within 14 days, once a mitigation is available, they must submit a final report detailing the vulnerability and any exploitation of it.

According to Doc McConnell, Head of Policy and Compliance, Finite State, “For many companies, the challenge isn’t simply reporting, it’s determining within a few hours whether a vulnerability exists inside their products, whether it’s being actively exploited, and who might be affected.”

(Doc is a former CISA Branch Chief and a former Senior Advisor for Cybersecurity Policy with the U.S. Office of Management and Budget.)

“The biggest obstacle isn’t paperwork, it’s visibility. Many companies lack accurate software inventories across their product lines, and have limited insight into third-party components embedded in products. Even more lack an in-place internal decision process to meet that 24-hour reporting mandate. 

“The CRA readiness gap persists across sectors: ICS, automotive, medical devices, consumer electronics, IoT, IT gear, mobile applications distributed to EU end users, embedded software and more.

“And are their legal and compliance departments ready to assess cyber resilience?”

The Manufacturer’s Guide to CRA Vulnerability Handling is worth reading: https://finitestate.io/resources/cra-vulnerability-handling-guide

Also worth reading is the CRA Vulnerability Reporting: September 2026 is Around the Corner: https://finitestate.io/blog/cra-article-14-september-2026-reporting-deadline

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading