The Cyber Resilience Act Starts Demanding Breach Reports
SCHEDULED85% CONFIDENCEThe date is set by the regulation itself, per the European Commission: "New Cyber Resilience Act reporting obligations take effect on 11 September 2026".[1]
The EU's Cyber Resilience Act reaches its first live phase: manufacturers of any product with digital elements sold in the EU must report actively exploited vulnerabilities and severe incidents to ENISA and their national CSIRT - an early warning within 24 hours, a full notification within 72, and a final report within 14 days.
1.00