The EU's New Cyber Security Law Gives Manufacturers 24 Hours to Report Flaws. Almost No One Is Ready.
The Cyber Resilience Act, which took effect in September, requires companies to report actively exploited vulnerabilities within one day. Security experts say the clock will break every manual process most vendors currently rely on.

Key points
- The EU Cyber Resilience Act (CRA) introduced a legally binding 24-hour reporting deadline for actively exploited vulnerabilities on 11 September 2024, covering all internet-connected hardware and software sold in the EU.
- Any company selling digital products in the EU falls under the law, regardless of where it is headquartered.
- Security experts warn that the data needed to file a compliant report currently lives across five or six disconnected internal systems, making manual compliance within 24 hours functionally impossible for most organisations.
- The CRA requires manufacturers to build security into products at the design stage rather than patch it in later, a shift experts compare in scale to the EU's GDPR data-protection rules.
- CISOs who treat software inventories as quarterly paperwork exercises will fail the requirement outright.
The EU Cyber Resilience Act is a binding regulation covering every piece of internet-connected hardware or software sold inside the European Union: routers, firewalls, operating systems, identity-management systems, security software and more. If your product connects online, it is in scope. So is your company, even if you've never set foot in Europe.
Discover an actively exploited vulnerability (a security flaw being used by attackers right now) and you have 24 hours to report it to the relevant EU authority. No grace period.
Why is 24 hours such a problem?
The information needed to file that report is scattered across systems never designed to talk to each other. Security-event logs sit in one place. Known-exploited-vulnerability alerts sit in another. The record of which software components are inside each product, called a Software Bill of Materials or SBOM, is somewhere else. Pulling all of that together by hand inside a single working day isn't realistic.
Joe Brinkley, director of offensive security research at penetration-testing firm Cobalt, put it plainly to CSO Online: the 24-hour window "completely kills" manual triage. "You just can't expect an analyst to catch a KEV alert, manually grep a static SBOM, and then dig through SIEM logs to see if a box is actively taking fire," he said. SIEM, short for Security Information and Event Management, is software companies use to collect and monitor security alerts.
The fix, Brinkley argues, is automation: the moment a flaw becomes public, systems need to automatically identify which products are affected and confirm whether exploitation is live. "If you don't automate that discovery phase, your team is going to spend 23 hours hunting for ground truth," he said. SBOMs need to be live, queryable data structures rather than compliance PDFs checked once a quarter.
| CRA obligation | Deadline or requirement |
|---|---|
| Report actively exploited vulnerability | Within 24 hours of discovery |
| Report severe security incident | Within 24 hours |
| Secure-by-design product development | Required at planning, design and build stages |
| Security updates and maintenance | Mandatory for product lifetime |
| Applies to non-EU companies | Yes, if product is sold in the EU |
Will this change how products are actually built?
Yes, and that is the bigger structural shift. The CRA doesn't just regulate reporting; it requires manufacturers to design security in from the start. Vincent Lomba, chief product security officer at Alcatel Lucent Enterprise, argues that hardware makers building AI chips and GPU processors will have to rethink core architectures. "Manufacturers are currently prioritising raw processing power over built-in resilience," he told CSO Online. "That can no longer be the case."
Artem Serebrov, director of product at PCA Cyber Security, draws a comparison to GDPR, the EU's data-protection rulebook. The parallel isn't entirely reassuring. Under GDPR, he notes, companies responded to breach-reporting obligations by quietly reducing how closely they monitored their own systems, because finding a problem triggered a reporting duty. The CRA carries the same risk.
We first covered this regulation on 17 September 2026, when our earlier story found that the hard part isn't the paperwork, it's knowing what you shipped. That framing holds. A 24-hour clock rewards companies with real-time visibility into their own products and punishes everyone else. Worse, it creates a quiet incentive for the unprepared to stay wilfully blind rather than invest in tooling that would make compliance possible.
Louise Horton, head of UK government affairs at NCC Group, frames it more charitably but lands in the same place: "Those that are most prepared will have already embedded secure-by-design principles into product development."
For organisations that haven't, the clock is already running.
Common questions
Who does the CRA actually apply to?
Any manufacturer or vendor selling internet-connected hardware or software products into the EU market, wherever in the world they are based.
What triggers the 24-hour reporting clock?
Discovery that a vulnerability in your product is being actively exploited. The clock starts at discovery, not at public disclosure.



