12 SEP 2026 — Since 11 September, any manufacturer selling a product with digital elements into the European Union has had 24 hours to report an actively exploited vulnerability in it. The clock starts when you become aware of the exploitation, not when you have a fix.
The obligation comes from the Cyber Resilience Act, and it reaches software and connected hardware alike. A vendor in Penang or Cebu shipping to European customers is inside it.
The three deadlines
An early warning is due within 24 hours of becoming aware of an actively exploited vulnerability in a product with digital elements. A fuller notification follows within 72 hours.
A final report is due no later than 14 days after a corrective measure becomes available, for exploited vulnerabilities, and within a month for severe incidents.
All of it goes through one route, the Single Reporting Platform operated by ENISA, the EU's cybersecurity agency. A manufacturer files once, with the national CSIRT of its main establishment and with ENISA together, not with each member state separately.
Reporting before you have an answer
The first two deadlines are designed to land while the manufacturer still knows very little.
Twenty-four hours after learning that something is being exploited, a vendor typically has a report from a customer or a researcher, a hypothesis, and no patch. Seventy-two hours in, the hypothesis may have changed. The regime asks for both filings anyway, and deliberately: the CSIRT network's value is in aggregating early, partial signals across manufacturers, which is a different purpose from the advisory a vendor eventually publishes.
This anticipates the first objection: that early disclosure tips off attackers. These reports go to CSIRTs and ENISA, not to the public. The exploitation is already happening — that is the trigger condition — so the information being shared is information an attacker already has.
Awareness is the contestable word
Every deadline here hangs on when a manufacturer became aware, and the Act does not supply a timestamp.
In practice awareness arrives through a support ticket, a researcher's email to an address nobody monitors, a customer's incident report, or a mention on a forum somebody eventually notices. Each of those has a different arrival time, and only one of them is logged in a way a regulator could later inspect.
The organisations that will struggle are not those acting in bad faith, but those where a report sits in an inbox for a fortnight before it reaches someone who can act on it. The practical compliance work is therefore internal routing, not form-filling. You need a defined intake, a named owner and a record of when each report landed.
Who is in scope
The obligation attaches to manufacturers of products with digital elements placed on the EU market. That is a wide net, and it catches firms that do not consider themselves software companies — an industrial controller, a consumer appliance with an app, a medical device, a piece of enterprise software sold through a European reseller.
For manufacturers in this region the significant detail is that market access, not establishment, is what triggers it. A company with no European office that sells into the EU through distributors is still a manufacturer placing a product on that market.
The 24-hour clock is also a clock that runs across time zones. A Singapore or Jakarta vendor learning of exploitation at 18:00 local time has a deadline that expires during a European working day, which makes the filing an operational-hours problem rather than a legal one.
Three regimes, one incident
A vendor with European customers can now owe several notifications about one event on different clocks. NIS2 obligations may apply to the operator running the product, GDPR's 72-hour breach notification applies if personal data is involved, and this adds a manufacturer-side duty on a 24-hour clock that is shorter than either.
These are not alternatives. An exploited vulnerability in a product that processes personal data, used by an essential entity, can trigger all three. They go to different recipients, ask for different content, and the shortest deadline sets the pace.
That is a real compliance burden, and the regime is not tidy. It is the predictable consequence of regulating the product, the operator and the data separately, which the EU has done.
What to do this month
Decide who files. The obligation is corporate and the deadline is 24 hours, so the answer cannot be discovered during an incident.
Then register with the Single Reporting Platform before you need it. An account created under deadline pressure, by somebody who has not seen the form, is the failure mode this predicts.
And write down what awareness means for your organisation — which inboxes, which tickets, which channels start the clock. That definition is what a regulator will examine after an incident, and it can only be set deliberately beforehand.
What to watch
The first enforcement action, and what it is for. A regime this new is defined less by its text than by whether the first case concerns a missed deadline, an inadequate report, or a manufacturer that argued it was not aware.
And whether the platform holds. A single EU-wide reporting gateway is a good design and a concentration point, and the first weeks of a mandatory system are when its capacity is discovered.