{
  "id": 6773711,
  "title": "EU's Cyber Resilience Act starts the 24-hour vulnerability clock",
  "url": "https://urgent.news/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock-6773711",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-11T11:34:41.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/5295821"
  },
  "original_language": "en",
  "account": "EU's Cyber Resilience Act, effective today, requires manufacturers of digitally-enabled products sold in the EU to report actively exploited vulnerabilities within a 24-hour window of discovery. This obligation, outlined in Article 14 of the rule, extends to both EU and non-EU manufacturers regardless of their location. The law mandates an initial 24-hour warning followed by a more comprehensive report within 72 hours. For severe security incidents, a final report must be submitted within 14 days of implementing corrective measures, or one month for serious occurrences. Darren Anstee, CTO for security at Netscout, emphasizes that these timely deadlines foster urgency, allowing organizations to promptly bolster defenses and deploy mitigating controls. Manufacturers are obligated to disclose these vulnerabilities and severe incidents to users and relevant cybersecurity authorities, typically the coordinating CSIRT in their respective EU member state or a designated team for non-EU manufacturers. Non-compliance may result in substantial fines, up to €15 million or 2.5% of the offender's annual turnover, whichever is greater. This act represents a critical step in the EU's ongoing effort to strengthen cybersecurity regulations across the bloc, with additional provisions, including the requirement for \"security by design and default,\" slated to take effect in 2027. Beyond mandating quicker responses to security flaws, the Cyber Resilience Act aims to enhance businesses' understanding of their software supply chains, requiring manufacturers to maintain a comprehensive view of their products and any related components throughout their lifecycle. This comprehensive approach is designed to minimize the number and impact of serious cyberattacks across the EU. As manufacturers navigate this evolving regulatory landscape, which already intersects with other EU cybersecurity laws such as NIS2, DORA, the Data Act, and the AI Act, the focus on secure development, effective vulnerability handling, and traceability in the software supply chain has become increasingly vital.",
  "summary": "Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "EU's Cyber Resilience Act starts the 24-hour vulnerability clock",
        "url": "https://urgent.news/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock",
        "published": "2026-09-11T11:34:41.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}