EU Gives Tech Manufacturers 24 Hours to Flag Active Cyber Exploits
EU manufacturers must now report actively exploited vulnerabilities and severe product-security incidents through a single ENISA portal, starting with a 24-hour warning. Most wider Cyber Resilience Act duties still wait until December 2027.
Manufacturers selling connected hardware or software in the European Union now face a running cyber-reporting clock. On September 11, the EU Agency for Cybersecurity launched the first operational version of a common portal for disclosing actively exploited vulnerabilities and severe security incidents under the Cyber Resilience Act.
The 30-second summary
- What happened? The EU activated mandatory incident reporting and opened ENISA's Single Reporting Platform.
- Why does it matter? Manufacturers can submit one report for coordination across national cyber-response teams instead of notifying multiple authorities separately.
- What is the catch? This is only the reporting phase of the law. Most product-security duties do not apply until December 2027, and the launch platform has practical limitations.
Key Number: A manufacturer must send an early warning within 24 hours of becoming aware of a reportable vulnerability or severe incident, followed by a fuller notification within 72 hours.
Which events trigger the new clock?
The requirement covers two categories. The first is a vulnerability for which reliable evidence shows that a malicious actor has exploited it without permission. The second is an incident severe enough to affect a digital product's ability to protect the availability, authenticity, integrity or confidentiality of its data or functions.
The rules apply to products with digital elements made available in the EU, including products already on the market. The trigger is when the manufacturer becomes aware of the qualifying event. ENISA says a company does not have to report an exploitation it already knew about before September 11, but it must report if awareness comes after that date, even when the underlying flaw was previously known.
One submission, several authorities
A manufacturer registers an assigned representative and chooses the national Computer Security Incident Response Team, or CSIRT, that coordinates its report. The portal simultaneously makes the notification available to ENISA, except in narrowly defined exceptional circumstances. The receiving CSIRT then shares it with relevant teams in other member states where the affected product is available.
After the first two notices, the final deadline depends on the event. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For a severe incident, it is due within one month of the 72-hour notification.
The first release is deliberately limited
The initial portal accepts mandatory reports only. Voluntary vulnerability reports are planned for a later phase, and ENISA says no application programming interface is available at launch, so submissions must be made through the web interface. The platform is initially available in English, while supporting documents are being translated.
Open-source software stewards are not yet subject to their equivalent reporting duty. That requirement begins on December 11, 2027, the same date most of the Cyber Resilience Act's wider product-security obligations become applicable.
Before we overstate the change
The portal does not by itself make a vulnerable product secure or guarantee that every manufacturer will identify a qualifying event on time. The system centralises notification and gives authorities a coordinated channel, while enforcement, reporting quality and the speed of corrective action will determine its practical impact. ENISA also acknowledges that platform guidance and functionality will evolve with operational experience.
What manufacturers need to prove next
The immediate test is operational: whether companies can recognise reportable events, select the correct coordinating CSIRT and meet short deadlines without sacrificing useful technical detail. The larger test arrives in 2027, when reporting becomes one part of a broader obligation to design, update and maintain digital products against cybersecurity risks.
Verified topics and entities
Sources and citations4 sources
External references used to support the reporting in this article.
Published by
NewTqnia Technology Policy Desk
An institutional editorial team within NewTqnia