Manufacturers selling connected devices and software in the European Union are now operating under a 24-hour cybersecurity reporting clock. The Cyber Resilience Act’s incident-reporting requirements took effect Sept. 11, 2026, creating an immediate operational obligation well before the law’s broader product-security rules become fully applicable.

The change matters beyond Europe. The requirements apply to products with digital elements made available in the EU, including products already on the market. That puts global software companies, device makers and other technology suppliers within scope when their products reach European customers.

The deadlines are now active

Under the new rules, manufacturers must submit an early warning within 24 hours after becoming aware of an actively exploited vulnerability or a severe incident affecting product security. A fuller notification is due within 72 hours.

For an exploited vulnerability, a final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, the final deadline is one month after the 72-hour notification, according to the European Commission’s implementation guidance.

Reports go through the European Union Agency for Cybersecurity’s Single Reporting Platform and are directed to the Computer Security Incident Response Team responsible for the manufacturer’s main establishment. The Commission says national market-surveillance authorities will enforce the requirements.

The business impact starts before full compliance

Most of the Cyber Resilience Act’s obligations will not apply until Dec. 11, 2027. The reporting requirement, however, is already live. That compresses the time available for security, product, engineering, legal and communications teams to determine whether a vulnerability is being exploited and assemble a regulator-ready account.

TechTarget reported that the rule reaches legacy products still in use, while IT Pro highlighted the difficulty of meeting the timeline when companies lack a clear inventory of third-party components.

Executives need an escalation path

The immediate management question is whether a company can identify the affected products, establish legal responsibility and escalate a confirmed event quickly enough to meet the first deadline. Product inventories, software bills of materials, documented ownership and rehearsed notification workflows are becoming operational necessities rather than longer-term compliance projects.

The new clock turns vulnerability management into an executive coordination test. Companies selling digital products in Europe may have only one business day to move from technical discovery to a formal warning, even when an incident begins outside normal working hours.