Cyber Resilience ActSep 10, 2026
EU Cyber Resilience Act to Enforce New Reporting Requirements
EU Cyber Resilience Act mandates 24-hour incident reporting for serious product security flaws.
Summary
The EU Cyber Resilience Act (CRA) enforcement begins, requiring businesses to report serious product security incidents to government authorities within 24 hours. This represents a significant tightening of incident disclosure timelines across the EU, affecting manufacturers, importers, and distributors of connected products. The regulation aims to improve transparency and enable faster coordinated response to emerging threats.
Entities
EU Cyber Resilience Act (CRA) (technology)