A New EU Reporting Deadline Started Today. Does It Apply to Your Business?

A New EU Reporting Deadline Started Today. Does It Apply to Your Business?

· by IDE Solutions

Short answer: As of today, September 11, 2026, the EU Cyber Resilience Act requires any business that manufactures or sells software or connected hardware in the EU to report an actively exploited vulnerability to ENISA within 24 hours, through a reporting portal that opened the same day. It applies to the products you build and place on the market, not to software you merely use inside your own company, so most small businesses running Microsoft 365 and a normal website are not directly affected yet. If you sell an app, a plugin, or a connected device, check your exposure now, because full certification duties follow in December 2027.

People hear "EU Cyber Resilience Act" and picture heavy industry, factories, and machinery directives that have nothing to do with a twenty-person services company. That assumption is wrong often enough to matter. The law is not about factories. It is about anything with "digital elements", which turns out to include a huge range of ordinary software: business apps, browser plugins, firmware for a connected sensor, and the backend of a SaaS product a small company built and now sells to its own customers.

A new part of that law took effect today, and unlike most EU compliance deadlines, it did not arrive with a long grace period. If your business builds or resells a digital product rather than only using one, the question of whether this reaches you is worth ten minutes this week, not next quarter.

Quick answers

What actually started on September 11, 2026? The Cyber Resilience Act's Article 14 reporting duty: manufacturers must now report an actively exploited vulnerability or a severe security incident to ENISA and their national CSIRT within set deadlines, using the newly launched Single Reporting Platform.

Does this apply if I just use Microsoft 365 and a normal website? No. The duty sits with the company that builds and places a digital product on the EU market, called the manufacturer. A company that only uses software internally is a user, not a manufacturer, under this law.

Does it apply if my company builds or sells an app or a connected product? Very likely yes, once it is made available commercially in the EU, regardless of how small the company is. Size affects the support you can get, not whether the duty applies.

Is this the same as NIS2? No. NIS2 covers organisations that operate certain kinds of services, and can reach a small supplier indirectly through a customer's requirements. The Cyber Resilience Act covers the product itself, wherever it is made and sold.

What changed today, in plain terms

The Cyber Resilience Act entered into force in December 2024, but most of its duties had a long lead-in. Today is the first hard deadline with teeth. From now on, a manufacturer of a product with digital elements that is being made available on the EU market has to report to ENISA, the EU cybersecurity agency, and the relevant national CSIRT (in Germany, the BSI) whenever a vulnerability in that product is being actively exploited, or a severe incident affects it.

The reporting itself runs on a staged clock: an early warning within 24 hours of becoming aware of the problem, a fuller technical notification within 72 hours, and a final report within 14 days for a vulnerability or one month for an incident. ENISA's Single Reporting Platform went live on the same day the duty became mandatory, so there was no window where the obligation existed without a way to fulfil it.

Who counts as a manufacturer here?

This is the part worth ten careful minutes, because the answer decides everything else. A manufacturer under the Cyber Resilience Act is whoever develops a product with digital elements and places it on the EU market under their own name, whether or not they wrote every line of it themselves. That covers standalone software you sell as a product, a mobile or web app you charge customers to use, firmware in a connected device, and software components you bundle into something you sell on.

It does not, on its own, cover a company that buys software from someone else and only runs it for internal use, and it does not turn every company with a custom website into a manufacturer just because the site has a contact form or a login page. The distinction the law draws is between building and placing a digital product on the market versus using one. Most professional services firms, agencies, and local businesses sit firmly on the using side.

Where a small business gets pulled in

The businesses that need to pay attention now are a narrower, specific group. If your company has built and sells a software product, even a small one, such as a booking widget, an industry-specific app, or a plugin for a bigger platform, you are very likely a manufacturer for that product. The same applies if you sell a connected physical device, a smart sensor, a point-of-sale terminal with its own firmware, or anything that talks to the internet and ships under your brand.

If that describes part of your business, the practical first step is not the 24-hour clock itself, it is building the internal habit of finding out about a vulnerability quickly enough that 24 hours is even achievable. That means a real process for vulnerability monitoring and incident response, not a folder nobody checks. A cloud security review that includes vulnerability management is the practical way to get that process in place before a report is ever due.

What if my business is not in scope? Can I ignore this entirely?

Mostly, for now. If you only consume software and cloud services, whoever built them carries the reporting duty, not you. But three things are worth knowing anyway. First, being a customer of an in-scope manufacturer means their compliance directly affects how fast you learn about a vulnerability in a tool you depend on, so it is worth confirming your suppliers take this seriously rather than assuming it. Second, procurement questionnaires from larger EU customers are starting to ask about Cyber Resilience Act readiness the same way they already ask about GDPR, so a "not applicable" answer needs to be an informed one, not a guess. Third, the scope of what counts as a digital product tends to widen as guidance matures, so a business that is safely out of scope today is worth rechecking again before December 2027.

Is December 2027 something to worry about now?

Not urgently, but it changes the size of the task. The reporting duty that started today is narrow: tell the authorities fast when something goes wrong. From December 11, 2027, the Cyber Resilience Act's full weight lands, including essential cybersecurity requirements built into the product itself, technical documentation, a formal conformity assessment, and CE marking that from that date includes cybersecurity for the first time. That is a product development and compliance project, not a reporting habit, and it needs a much longer runway than the 24-hour clock does.

The BSI has published implementation guidance for manufacturers working toward that 2027 deadline, and the Act includes specific support measures for small and micro businesses, guidance documents, helpdesks, and simplified documentation, precisely because the drafters expected smaller manufacturers to need the help.

Reporting obligation vs full compliance, at a glance

  Reporting duty (Article 14) Full application (2027)
Effective dateSeptember 11, 2026December 11, 2027
What it requiresReport exploited vulnerabilities and severe incidents fastBuild products to essential security requirements, document them, get CE marking
Deadline once triggered24 hours, 72 hours, 14 days or one monthOngoing, checked before a product can carry CE marking
Who reports toENISA and national CSIRT (Germany: BSI), via the Single Reporting PlatformA notified conformity assessment body, depending on product risk class

What happens if an in-scope business ignores this?

The penalties are not symbolic. Under Article 64 of the Act, breaching the essential security requirements or the core manufacturer obligations can bring fines of up to fifteen million euro or 2.5 percent of worldwide annual turnover, whichever is higher. Other breaches top out lower, and giving authorities inaccurate or misleading information carries its own separate penalty band. For a small manufacturer, the practical risk before December 2027 is less the fine itself and more losing a contract because a customer's procurement team asked a Cyber Resilience Act question the business could not answer. A short IT governance and compliance review that maps where your products actually sit against the Act closes that gap before it shows up in a lost deal.

What to check this week

Three things, and none of them need a lawyer yet. List anything your business sells or licenses that includes software, a firmware update mechanism, or an internet connection, and ask plainly whether your company is the one that places it on the market. If the answer is yes for anything, confirm you have a real way to learn about a vulnerability in that product quickly, because the 24-hour clock only starts once you become aware, and "we never found out" is not a safe place to be. If the answer is no across the board, note that down with the reasoning, because the same question will come back on a customer's compliance questionnaire before the end of the year.

This is a mapping exercise, not a certification project. It takes an afternoon, and it is the kind of thing that gets skipped because the headline sounds like it belongs to hardware manufacturers, not a services business with one small software product on the side.

We map where you actually stand under the Cyber Resilience Act

We check whether anything your business builds or sells counts as an in-scope product, and if it does, we put a real vulnerability monitoring and reporting process behind it so the 24-hour clock is something you can meet, not something you find out about after the fact.

Where the answer is that you are a user rather than a manufacturer, you get that in writing too, so the next questionnaire is a five-minute answer instead of a research project.

More Articles