Wire · regulatory
The EU Cyber Resilience Act's vulnerability and incident reporting requirements are now live
◆ Sectors
◆ Geography
◆ Source
◆ Verified
Fusion42 · 11 September 2026 · Fusion42 review
The EU Cyber Resilience Act (CRA) introduces mandatory vulnerability and incident reporting for manufacturers of products with digital elements from 11 September 2026, requiring ongoing cybersecurity risk management and reporting of actively exploited vulnerabilities and severe incidents.
This Wire brief sits within Fusion42's coverage of Cybersecurity, and 4 sources have reported it between 4 Sep 2026 and 12 Sep 2026.
◆ ◆ The Wire takeaway
The rules for cyber incident reporting under the EU Cyber Resilience Act now bind all manufacturers of digital products in the EU. You need to arrange compliance before September 2026 to avoid market access loss and fines.
◆ Coverage
4 sources · first reported 4 Sep 2026 · latest 12 Sep 2026
◆ Related on Wire
◆ Topics