ComplianceSME

Compliance dates · 11 September 2026 · EU

Cyber Resilience Act reporting starts on 11 September 2026 with a 24 hour clock

From 11 September 2026 the Cyber Resilience Act reporting regime runs. An actively exploited vulnerability or a severe incident in a product with digital elements carries a 24 hour early warning to ENISA and to the national CSIRT.

The clock is the hard part. Twenty-four hours is short enough that the reporting route has to exist before the first report is needed, not be assembled once something has gone wrong. ENISA and the national CSIRT are both named, so the early warning runs to two destinations rather than one.

Manufacturers of products with digital elements

Any manufacturer placing hardware or software with digital elements on the EU market, including small software vendors. Placing the product on the EU market is the test, not where the manufacturer sits.

Standing up a reporting route

The Cyber Resilience Act system

Reporting is one duty inside the Cyber Resilience Act, and the system covers the Regulation whole.

Cyber Resilience Act £1,500

Security requirements for products with digital elements placed on the EU market.

Regulation (EU) 2024/2847 · European Union

Verified 19 August 2026.

Back to every EU and UK compliance deadline left in 2026