- Start
- Sep 11, 202675% CONFIDENCEfrom the source
The Cyber Resilience Act Starts Demanding Breach Reports
- The reporting duties bite two years and three months before the rest of the Act, and they apply to products already on the market, not only to new ones. [S]
- The clock is deliberately short: 24 hours for an early warning, 72 hours for the full notification, 14 days after a fix exists for an actively exploited vulnerability and one month for a severe incident. [S]
- It is the first EU-wide obligation to tell a regulator that a vulnerability in a shipped product is being exploited, rather than only that personal data leaked. [S]
References 285% CONFIDENCE
The first entry is always the pin's source. Overall confidence is a weighted average of how firmly each reference supports the start and end times used above; a reference counts half as much for every 180 days older than the newest.
- [1]75%commission.europa.eu/news-and-media/news/safer-and-more-secure-digital-products-2026-09-11_encommission.europa.eu· Posted Sep 21, 2026· Starts Sep 11, 2026 ✓· 50% of score
The date is set by the regulation itself, per the European Commission: "New Cyber Resilience Act reporting obligations take effect on 11 September 2026".
- [2]95%Cyber Resilience Act - Reporting obligationsdigital-strategy.ec.europa.eu· Added Sep 21, 2026· 50% of score
The Commission's own policy page sets out which incidents must be reported, to whom, and in what time.[1]
Suggest a correction
Something missing or wrong? Say it in your own words: a link that backs this pin up, a different start or end date and why, or a fact it lacks or gets wrong. The AI checks it against this pin's sources, searches for better ones, and adds any page that backs you up. The pin's own sources still count most.