DEV Community

Tanod Labs
Tanod Labs

Posted on Originally published at tanod.dev

Cyber Resilience Act reporting since 11 September 2026: a checklist for small software vendors

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) mostly applies from 11 December 2027, but its reporting duty for manufacturers has applied since 11 September 2026. It covers products with digital elements on the EU market, including products placed on the market before 2027. This page summarises what the published legal commentary says; it is not legal advice, so check the regulation and ENISA's guidance for your case.

What must be reported

  • Actively exploited vulnerabilities in your product: there is reliable evidence that a malicious actor has used the vulnerability without the system owner's permission. A vulnerability found through good-faith research is not reportable on that basis alone.
  • Severe incidents that affect the security of your product.

Commentary also notes there is no duty to report, retroactively, exploitation you already knew about before 11 September 2026.

The clock

  • 24 hours: early warning, counted from when you become aware, meaning an initial assessment gives you reasonable certainty that exploitation is happening.
  • 72 hours: the notification with more detail.
  • 14 days after a fix or mitigation is available, for an exploited vulnerability; one month after the 72-hour notification, for a severe incident: the final report.

Where to report

ENISA's Single Reporting Platform went live for these duties. One submission reaches ENISA and the CSIRT designated as coordinator, normally the one where your main EU establishment is; manufacturers outside the EU report through their EU authorised representative. Secondary sources describe access through EU Login with multi-factor authentication. Register before you need it: a 24-hour deadline leaves no time to set up accounts.

A practical setup for a small team

  • A reporting inbox and a contact point. Annex I of the regulation expects a published way for outsiders to report vulnerabilities and a process to fix them. A /.well-known/security.txt file (RFC 9116) with a monitored address is the common way to publish the contact; practitioners recommend it, the regulation does not name it.
  • A written coordinated vulnerability disclosure policy that says how reports are received, acknowledged and fixed.
  • An on-call rule for the 24-hour clock: who decides that exploitation is "reasonably certain", and who files.
  • A component list (SBOM) for each product, so you can tell within hours whether a newly exploited library is inside it.
  • Watch exploitation signals for the components you ship, such as known-exploited vulnerability catalogues, so awareness does not depend on a customer telling you.

Penalties

Fines under the regulation can reach EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher, for the most serious breaches of the essential requirements.

Sources

Kept current at https://tanod.dev/learn/cyber-resilience-act-reporting-small-vendors.html. Not legal advice; the regulation and ENISA's guidance prevail.

Top comments (0)