Manufacturers selling products with digital elements in the EU must now report actively exploited vulnerabilities to cybersecurity authorities under the Cyber Resilience Act's mandatory reporting rules.
The reporting duties set out in Article 14 of the CRA became applicable today. Subject to the regulation's exemptions, they apply to manufacturers of products with digital elements made available in the EU, regardless of where those manufacturers are based.
Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours.
The same deadlines apply to severe incidents affecting the security of products with digital elements.
The only difference in timing is related to the final report. Manufacturers must provide a final report on an actively exploited vulnerability within 14 days of making a corrective or mitigating measure available. For serious incidents, the final report is due one month after the first report.
Darren Anstee, CTO for security at Netscout, said the reporting deadlines introduce much-needed urgency in working toward global cyber resilience.
"The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said.
"Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk."
EU and non-EU manufacturers must file these reports through ENISA's Single Reporting Platform (SRP).
Notifications are addressed to the coordinating computer security incident response team (CSIRT) determined under the CRA. For an EU manufacturer, this is generally the CSIRT for the member state where it has its main establishment; separate rules determine the coordinator for manufacturers based outside the bloc.
Manufacturers must also inform affected users, where appropriate, about actively exploited vulnerabilities or severe incidents. The CRA states that users must be informed of available corrections or mitigations without undue delay.
Generally, failures under the CRA are punishable by varying tiers of fines, the most serious of which can reach €15 million ($17.4 million) or 2.5 percent of the offender's annual turnover, whichever is higher.
The reporting duties that took effect today are classified as core responsibilities under the act, meaning failures to comply with them could lead to the maximum fines being issued.
They are the latest step in the EU's plan to drip-feed tighter security regulations on companies operating in the bloc.
Most remaining CRA provisions become applicable on December 11, 2027, at which time manufacturers will also be required to embed security by design and default. That means no default passwords and security updates are no longer optional.
Products covered by the CRA will also have to undergo the applicable conformity assessment before being placed on the EU market and bearing a CE mark.
The CRA's new rules are not just intended to accelerate manufacturers' responses to security flaws. They are also intended to give businesses a better understanding of their software supply chains.
With the reporting clock starting as soon as manufacturers become aware of an issue, they cannot afford to begin mapping an affected product only after a vulnerability or incident emerges. They need a comprehensive view of the affected product and any related products that may share the flaw if they are to meet the deadlines.
Furthermore, those requirements demand that manufacturers maintain this understanding throughout each product's lifecycle.
Creating a software bill of materials (SBOM) when a product is launched is one thing. The SBOM becomes a mandatory requirement when most of the CRA's remaining provisions become applicable next year.
Maintaining that security snapshot over time, however, is intended to help reduce the number and impact of serious cyberattacks across the EU.
"What all this means for manufacturers is that secure development, effective vulnerability handling, and traceability across the software supply chain should be elevated to the top of their priority list," said Eran Kinsbruner, veep of product marketing at Checkmarx.
"Modern applications are assembled from a complex ecosystem of components, with combinations of proprietary code, open-source packages, third-party components and, increasingly, AI models and services all interconnected," he added. "Organizations need to understand these components, their dependencies and the risks they introduce."
Given enough time, the CRA looks set to improve cyber resilience across the board. However, lawyers warn that manufacturers, particularly those outside heavily regulated sectors, must now contend with a growing body of overlapping rules.
"The CRA is arriving as organizations are already grappling with a growing body of Digital Decade legislation, including NIS2, DORA, the Data Act, and the AI Act," said Heidi Waem, data, privacy and cybersecurity partner at DLA Piper.
"We're seeing the compliance challenge for many businesses evolving beyond understanding single regulations in isolation, but determining how multiple frameworks interact, where requirements overlap and how compliance programmes can be coordinated across them."
John Magee, partner and global co-chair of data, privacy, and cybersecurity at the same law firm, added: "Even now we're seeing the breadth of the regulation's reach catching organizations off guard.
"Many still associate the CRA primarily with consumer IoT devices, when in reality it applies to a much broader pool of products with digital elements. For compliance teams already very busy managing multiple Digital Decade initiatives, there is a risk that this first wave of CRA obligations has arrived sooner, and with a wider impact, than they had expected." ®
Source: The register