Wire · regulatory
EU Cyber Resilience Act: Vulnerability and incident reporting obligations now apply and ...
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 12 September 2026 · Fusion42 review
The EU Cyber Resilience Act (CRA) reporting obligations under Article 14 became applicable from 11 September 2026, requiring manufacturers of products with digital elements to report actively exploited vulnerabilities and severe incidents via ENISA's Single Reporting Platform (SRP), which went live simultaneously. The CRA fully applies from 11 December 2027, and reporting obligations cover both new and legacy products, including after support ends.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 4 sources have reported it between 4 Sep 2026 and 12 Sep 2026.
◆ ◆ The Wire takeaway
Your security product must be ready to report vulnerabilities to ENISA and national CSIRTs from now, or face compliance risk. Get your reporting and user notification process operational immediately to avoid market access issues in Europe.
◆ Coverage
4 sources · first reported 4 Sep 2026 · latest 12 Sep 2026
◆ Related on Wire
◆ Topics