New cybersecurity rules for digital products come into force in the EU

illustrative, cybersecurity / Getty Images
Фото: illustrative, cybersecurity / Getty Images

On September 11, new Cyber Resilience Act (CRA) requirements regarding the reporting of cyber incidents and vulnerabilities came into force in the European Union. Manufacturers of software, hardware and other products with digital elements are now obliged to promptly inform about serious incidents and vulnerabilities that are already actively exploited by attackers.

This concerns Article 14 of the Cyber Resilience Act. The regulation itself entered into force back in December 2024 and will fully apply from December 11, 2027, but some of its provisions are being introduced gradually. The requirements for mandatory reporting began to apply exactly on September 11, 2026.

The rules apply to manufacturers of so-called products with digital elements. This category includes software and hardware products, as well as related components offered on the EU market.

Incident must be reported within 24 hours

If a manufacturer learns of an actively exploited vulnerability or a serious incident affecting product security, it must submit an initial alert within 24 hours.

Within 72 hours after discovery, a more complete notification must be provided with available information about the vulnerability or incident and an assessment of its consequences.

For an actively exploited vulnerability, a final report must be submitted no later than 14 days after a fix or other mitigation measure becomes available. For a serious cyber incident, a final report must be submitted within one month after the 72-hour notification.

Single reporting platform launched

Simultaneously with the entry into force of the new requirements, the EU Agency for Cybersecurity ENISA is launching the CRA Single Reporting Platform. Through it, a manufacturer can submit one notification instead of informing authorities in different EU countries separately.

A company chooses the relevant national CSIRT - computer incident response team, which is usually determined by the manufacturer's principal place of registration. The information is also transmitted to ENISA and, if necessary, to competent authorities of other EU states where the product is sold.

The new rules are also important for Ukrainian IT and technology companies if their products fall under the CRA and are present on the EU market. Moreover, the reporting obligations apply not only to new products that will appear after the full launch of the CRA in 2027, but also to products within the scope of the regulation that are already on the EU market.

The main part of the Cyber Resilience Act will apply from December 2027. It will establish broader mandatory cybersecurity requirements for products throughout their life cycle - from design and development to release of updates and elimination of vulnerabilities.

Based on: European Commission, ENISA, Rzeczpospolita

analytics