Article
EU Cyber Resilience Act's New Vulnerability And Incident Reporting Requirements For Products With Digital Elements Entered Into Force
Starting September 11, 2026, manufacturers of digital products in the EU must report cybersecurity vulnerabilities and incidents within strict 24-hour and 72-hour deadlines under the new Cyber Resilience Act. Companies face penalties up to €15 million or 2.5% of global turnover for non-compliance, requiring immediate preparation of incident response procedures and assessment of product portfolios to meet these unprecedented product-focused cybersecurity obligations.
Steptoe LLP