As of yesterday, digital manufacturers must report already exploited vulnerabilities to the EU
A story the morning press did not cover: as of September 11, Article 14 of the cyber resilience regulation applies. The single reporting platform managed by ENISA has been operational since the same date.
As of September 11, 2026, Article 14 of Regulation (EU) 2024/2847, the text known as the Cyber Resilience Act, applies. From that date, those who place products with digital elements on the Union market have a new obligation: to report actively exploited vulnerabilities and serious incidents. The deadline and its content are reconstructed from the analysis by law firm Crowell & Moring, which relies on the regulation and the Commission’s implementing acts, and from the note by Cloud Security Alliance Labs, built on the European Commission’s guidelines of July 27, 2026 and on ENISA’s communications.
It is worth focusing on the difference between the two objects of the rule, because that is the reason this obligation carries weight. A vulnerability is a flaw in the product; an actively exploited vulnerability is a flaw that someone is already using. The obligation therefore does not concern the totality of known problems in a piece of software or a connected device, but the cases in which the attack is underway — those in which a delay in reporting translates into harm for whoever uses that product.
The infrastructure
The European cybersecurity agency has stated that the single reporting platform has been operational since September 11, 2026, and that the public address would be made known before its launch. This is the entry point through which manufacturers’ notifications reach the competent authorities: a single channel in place of dispersion among national administrations.
There is then a second chain, concerning users. Manufacturers must inform affected parties without undue delay; if they fail to do so, the national computer security incident response team — the CSIRT — can notify them directly. This is a substitution clause: the public authority steps in for the company when the company remains silent.
The reporting obligation comes before the rest of the regulation: full application of the Cyber Resilience Act is set for December 11, 2027.
The sequence is not accidental. First the alarm system is switched on, then the overall obligations on product requirements come into force. For manufacturers, this means that the immediate compliance requirement is procedural — knowing who reports, how, and within what timeframe — while the substantive adaptation of products has a longer horizon.
Why it also concerns non-European entities
The rule applies to products placed on the Union market, not to European companies. Anyone selling connected devices or software in the twenty-seven countries falls within scope, regardless of where they are based. This is the same logic of territorial extension that the Union has already employed in other digital regulations.
What we do not know
The material consulted does not indicate the number of reports received in the platform’s first hours of operation, nor the public address through which the channel was opened. It does not indicate the exact deadlines within which the notification must be made, nor the sanctions regime applicable to those who fail to report: these are elements that the regulation and the implementing acts define, but that the sources available to us do not report, and which we therefore do not write.
The established fact is the calendar: reporting obligation from September 11, 2026, full application of the regulation from December 11, 2027.
← Archive · Front page · Past editorials · Report an error · Original article (in Italian)