← Back

Wire · regulatory

New EU Reporting Obligation for Software Vulnerabilities

Published

15 September 2026

Topic

regulatory

◆ Sectors

Cybersecurity

◆ Geography

European Union

◆ Source

Read at lexology.com →

◆ Verified

Fusion42 · 16 September 2026 · Fusion42 review

The EU Cyber Resilience Act, effective from 11 September 2026, mandates all companies providing software to report actively exploited vulnerabilities and security incidents to authorities and users, with fines up to EUR 15 million or 2.5% of global turnover for non-compliance. This law targets broad software security challenges amid rising cybercrime threats enhanced by AI.

This Wire brief sits within Fusion42's coverage of Cybersecurity, and 8 sources have reported it between 4 Sep 2026 and 23 Sep 2026.

◆ ◆ The Wire takeaway

You must now build processes to report security flaws directly to authorities and users or face heavy fines. This opens a door for compliance tools that simplify EU-wide vulnerability reporting for your software customers.

◆ Coverage

8 sources · first reported 4 Sep 2026 · latest 23 Sep 2026

◆ Related on Wire

◆ Topics

Cybersecurityeu-cyber-resilience-actsoftware-securitycybercrimeregulatory-complianceai-threats