← Back

Wire · regulatory

The EU Cyber Resilience Act's vulnerability and incident reporting requirements are now live

Published

11 September 2026

Topic

regulatory

Sectors

Cybersecurity

Geography

Europe

Source

Read at traverssmith.com

Verified

Fusion42 · 11 September 2026 · Fusion42 review

The EU Cyber Resilience Act (CRA) introduces mandatory vulnerability and incident reporting for manufacturers of products with digital elements from 11 September 2026, requiring ongoing cybersecurity risk management and reporting of actively exploited vulnerabilities and severe incidents.

This Wire brief sits within Fusion42's coverage of Cybersecurity, and 4 sources have reported it between 4 Sep 2026 and 12 Sep 2026.

◆ The Wire takeaway

The rules for cyber incident reporting under the EU Cyber Resilience Act now bind all manufacturers of digital products in the EU. You need to arrange compliance before September 2026 to avoid market access loss and fines.

Coverage

4 sources · first reported 4 Sep 2026 · latest 12 Sep 2026

Related on Wire

Topics

Cybersecuritycyber-resilience-acteu-regulationvulnerability-reportingincident-reportingproduct-security