Article
Ready, respond, report: the Cyber Resilience Act’s reporting regime is here
The EU's Cyber Resilience Act introduces mandatory vulnerability and incident reporting obligations for manufacturers of digital products starting 11 September 2026, well before the broader regulatory framework takes effect. Manufacturers must navigate tight reporting deadlines, determine when they become "aware" of security events, and establish governance structures to comply with 24-hour early warnings and subsequent detailed notifications through a platform that is not yet operational.
CMS Wistrand