Skip to content

Security1 publisher2 min readPublished

The EU's 24-hour exploitation report binds product manufacturers from September 11

The Cyber Resilience Act does not fully apply until December 11, 2027, yet its Article 14 early warning binds 15 months earlier, starting from the moment a manufacturer is reasonably certain a product is being exploited.

The Watch · Security desk

Illustration accompanying The EU's 24-hour exploitation report binds product manufacturers from September 11

What happened

  • From September 11, any manufacturer selling a connected product in the European Union must report an actively exploited vulnerability to authorities within 24 hours of confirming it.
  • Article 14 sets a cascade: early warning at 24 hours, a fuller notification at 72 hours, and a final report within 14 days of a fix becoming available, extended to one month for severe incidents.
  • Filing is single-entry through an ENISA-operated platform, with the receiving national CSIRT fanning the notification out to other member states where the product is sold and ENISA copied in parallel.
  • Scope is products with digital elements placed on the EU market, which takes in enterprise software, consumer IoT, industrial controllers and much of the component software underneath them.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure A distributor that rebrands or substantially modifies someone else's device inherits the manufacturer's obligations outright, so companies that wrote none of the code now own the 24-hour filing.
  • constraint Because the reporting duty outlives end of support, retiring a product line no longer closes the obligation, and legacy installed bases stay in scope for as long as they are being exploited.
  • decision Someone has to be able to sign a regulatory filing in the first hours of an incident, which moves the call on whether exploitation is real out of engineering and into a role with legal authority.
  • contradiction The Commission says the platform will be operational by the September date after functional and security testing, though ready-by-the-deadline leaves no window to rehearse a submission.

The trigger is a reasonable degree of certainty that a vulnerability is being exploited, or that an incident has severely compromised product security, and that call has to be made in hours, usually on partial telemetry [7]. A manufacturer cannot slow the clock by not looking: the standard does not allow the duty to be deferred by declining to investigate [7].

Article 14 attaches on September 11, 2026 [1][17], while the CRA's requirement that manufacturers publish a coordinated vulnerability disclosure policy does not apply until December 2027 [13]. For those 15 months, manufacturers owe regulators a 24-hour report on exploitation they may only hear about through intake channels they are not yet obliged to run [18].

The ceiling for breaching core manufacturer obligations is 15 million euros or 2.5% of global annual turnover, whichever is higher [10]. Divide 15 million by 0.025 and the crossover sits at 600 million euros of turnover [16]. Below that, the fixed sum is the exposure; above it, the percentage takes over and keeps climbing.

The harmonised standards that will define what adequate compliance looks like are still working through public enquiry, so the processes being built this month are being built against a moving target [12]. That affects the 72-hour and 14-day filings more than the 24-hour one, because the early warning is a short factual notice while the later reports are where a regulator can second-guess method.

Downstream of the manufacturers, the change is about whose clock governs. Enterprise buyers will start receiving vendor notifications on the vendor's schedule rather than their own, which requires a defined route from a supplier advisory into incident triage, plus a fast read on whether the same event also triggers duties under NIS2 or DORA [14].

Adobe confirmed this week that a maximum-severity Magento flaw, CVE-2026-75650, has been exploited against merchants since September 4 [15]. That sequence began before the duty attached. The same disclosure a week later would have put a 24-hour early warning into a designated national CSIRT, and through it into every member state where the product is sold [15][5].

What to watch

  • Whether the ENISA Single Reporting Platform is live and accepting Article 14 early warnings on September 11, or whether national CSIRTs fall back to email intake.
  • Publication of the harmonised standards after public enquiry, which is what will define adequate compliance for the 72-hour and 14-day filings.
  • The first enforcement action, and in particular whether it lands on a rebranding distributor rather than an original manufacturer.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories