Security2 publishers2 min readPublished
Manufacturers selling into the EU now owe ENISA a 24-hour warning on exploited flaws
The Cyber Resilience Act's vulnerability reporting duties are already in force, well before the December 2027 date that governs most of the regulation, and they sit alongside five other disclosure regimes whose clocks start differently.
The Watch · Security desk
What happened
- Since September 11, 2026, a manufacturer selling products with digital elements into the EU must send ENISA and the relevant national CSIRT an early warning within 24 hours on an actively exploited vulnerability.
- SC World reports the initial filing goes through ENISA's Single Reporting Platform, and that the 24 hours run from when the company learns of the vulnerability.
- The obligation covers products already on the market, not only products placed on it after the reporting rules took effect.
- Most of the Cyber Resilience Act still does not legally apply until December 2027, but its reporting obligations were separated out and started early.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure A vendor's early warning is what tells its regulated customers they have a reportable event, so the vendor's filing time sets when a bank's own notification clocks begin.
- decision Declaring a vulnerability actively exploited now commits the manufacturer to a filing inside 24 hours, so a named on-call role has to hold that call.
- constraint One incident at a listed multinational that ships software can start four regimes at once, so an intake process wired to a single deadline will miss filings under the others.
The other disclosure clocks do not all start where the CRA's does. Under DORA the first notification is due four hours after an incident is classified as major, and in no case later than 24 hours after the firm became aware of it [9]. The SEC's Form 8-K Item 1.05 allows four business days from the determination that an incident is material [10]. Sysdig's write-up groups those two together: each begins with a judgment the organisation makes, not with discovery [13].
GDPR Article 33 runs 72 hours from awareness of a personal data breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms [7]. Under NIS2 Article 23 the early warning is due 24 hours after awareness of a significant incident, with a fuller notification at 72 hours and a final report at one month [8]. CISA was expected to finalise CIRCIA in September 2026, and the rule is expected to require a report within 72 hours of reasonably believing a covered incident occurred, plus a report within 24 hours of disbursing a ransom payment [11].
Sysdig counts six regimes with similar but not identical deadlines, recipients and forms, and says a single incident at a multinational financial institution that ships software and has US listings can plausibly trigger four of them at once [12]. Counting initial notifications only, nothing in that set falls due sooner than the CRA's 24 hours except DORA's four, and DORA's four begin at classification [22].
The reporting duty is live for 15 months before the rest of the CRA applies: September 11, 2026 to December 11, 2027 [20]. It covers products already on the market, so the intake path has to work for software and hardware that shipped before anyone drafted a CRA process [5]. Neither write-up states a penalty for a missed early warning [24].
Sysdig also notes that for a software vendor selling into highly regulated industries, its own notification is the event that starts its customers' clocks [6].
Coverage is wide. Lee, writing in SC World's notes for Paul's Security Weekly #944, puts baby monitors, smart watches, applications and connectable hardware and software in scope, with compliant products carrying the CE marking [17]. The European Commission published practical guidance for manufacturers and developers earlier in the summer [15]. It runs 84 pages [16]. "Start getting processes, reporting, etc. setup now, it'll be December 11th 2027 before you know it," Lee wrote [18].
What to watch
- Whether ENISA publishes filing volumes from the Single Reporting Platform, showing who is actually sending early warnings.
- A first national action against a manufacturer for a late or missing 24-hour early warning.
- Whether the Commission revises its guidance on what counts as an actively exploited vulnerability for the 24-hour trigger.