← Back

Wire · regulatory

Old Products, New Obligations: EU Cyber Resilience Act Reporting Is Now Live

Published

16 September 2026

Topic

regulatory

◆ Sectors

Cybersecurity

◆ Geography

Europe

◆ Source

Read at mofo.com →

◆ Verified

Fusion42 · 16 September 2026 · Fusion42 review

The EU Cyber Resilience Act's reporting requirements for actively exploited vulnerabilities and severe security incidents for products with digital elements became effective on September 11, 2026, ahead of broader cybersecurity obligations starting December 11, 2027.

This Wire brief sits within Fusion42's coverage of Cybersecurity, and 8 sources have reported it between 4 Sep 2026 and 23 Sep 2026.

◆ ◆ The Wire takeaway

You must prepare your product security and incident response processes immediately to comply with early EU disclosure requirements. Your older digital products now face active compliance demands that could block market access without new reporting workflows.

◆ Coverage

8 sources · first reported 4 Sep 2026 · latest 23 Sep 2026

◆ Related on Wire

◆ Topics

Cybersecurityeucybersecuritycompliancereportingsecurity-incidents