惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
J
Java Code Geeks
I
InfoQ
腾讯CDC
Vercel News
Vercel News
IT之家
IT之家
V
Visual Studio Blog
P
Proofpoint News Feed
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
G
Google Developers Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - 叶小钗
有赞技术团队
有赞技术团队
月光博客
月光博客
Martin Fowler
Martin Fowler
量子位
L
LangChain Blog
B
Blog
Last Week in AI
Last Week in AI
博客园 - 司徒正美
Microsoft Security Blog
Microsoft Security Blog
博客园 - 聂微东
Microsoft Azure Blog
Microsoft Azure Blog
A
About on SuperTechFans

Privacy & Cybersecurity Law Blog

Delaware Expands State Privacy Law Dutch DPA Fines Uber Over Automated Decisions Affecting Drivers European Commission Designates ChatGPT, Reddit, and Roblox Under the Digital Services Act China Issues New Rules on Cyberspace Security Inspection Court Approves Meta Settlement With 29 States Over Alleged Harms to Children and Teens FTC Proposes Enforcement Policy Statement on Personalized Pricing New Jersey Enacts the Kids Code Act with Privacy-by-Default and Safety-by-Design Obligations White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations FTC, California and Utah Sue Telehealth Company Hims & Hers for Deceptive and Unlawful Privacy Practices CalPrivacy Settles with Two Data Brokers over Registration Failures and Privacy Violations New York Attorney General Releases Final Rules for SAFE for Kids Act EDPB Adopts Guidelines on Anonymous Data, Web Scraping, and Blockchain China Publishes Official Q&A on Administrative Policies for Cross-Border Data Transfers Hawaii Enacts AI Companion Disclosure and Safety Law EDPB Calls for Review of EU-U.S. Data Privacy Framework After U.S. Supreme Court Decision on FTC Independence CNIL Issues FAQs on Recommendation for Tracking Pixels in Emails European Commission Issues Guidance on the Cyber Resilience Act European Commission Issues EU AI Act Transparency Guidelines EU Digital Omnibus on AI Enters Into Force Connecticut AG Leads Multistate Settlement With 23andMe Over 2023 Data Breach CalPrivacy Targets Gig Economy Tech Platforms in First CCPA Compliance Audit New Jersey Adopts New Data Broker Registration Regime and Sensitive Data Sale and Licensing Restrictions CISA Plans to Finalize Cyber Incident Reporting Regulations in September 2026 Illinois Governor Signs Frontier AI Model Law New Hampshire Amends the NHDPA to Prohibit the Sale of Children’s Personal Data Canada’s Proposed Social Media Ban for Children and Chatbot Regulation: Bill C-34’s Impact on Platforms European Commission Unveils Cybersecurity and AI Action Plan European Commission Refers Four Member States to CJEU Over NIS2 Transposition Delays EDPB Opens Public Consultation on New Personal Data Breach Notification Template European Commission Advances New Proposal to Expand Cloud Capacity and AI Infrastructure
EU Cyber Resilience Act Reporting Obligations Take Effect...
2026-09-11 · via Privacy & Cybersecurity Law Blog

As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act (“CRA”). Products with digital elements include products that can be connected, directly or indirectly, to a device or network. This can include a wide range of connected consumer products and related apps.

The CRA entered into force on December 10, 2024. While the CRA’s main substantive obligations will apply from December 11, 2027, the incident reporting obligations take effect on September 11, 2026. Under such obligations, manufacturers are required to notify actively exploited vulnerabilities and severe incidents affecting the security of their products. This reporting obligation is one of the CRA’s first operational compliance requirements to take effect and is intended to support faster information sharing among relevant EU cybersecurity authorities.

Under the CRA, manufacturers that become aware of an actively exploited vulnerability or a severe incident with an impact on the security of a product with digital elements must follow a staged reporting process. The reporting timelines are as follows:

  • Early Warning: An early warning notification must be submitted within 24 hours of awareness.
  • Full Notification: A full notification must be submitted within 72 hours of awareness.
  • Final Report: A final report must be submitted within 14 days after a corrective measure becomes available in the case of an actively exploited vulnerability, and within one month in the case of a severe incident.

The CRA provides for a single reporting channel rather than multiple parallel submissions. Manufacturers must report through the CRA Single Reporting Platform. The notification is directed to the Computer Security Incident Response Team (“CSIRT”) of the EU Member State where the manufacturer has its main establishment and, except in particularly exceptional circumstances, the information is also made available to the EU Agency for Cybersecurity (“ENISA”). The CSIRT that first receives the notification is then expected to share the notification, without delay, with the CSIRTs in the other EU Member States where the affected product with digital elements has been made available.

The reporting framework includes a limited mechanism for delaying broader dissemination. In exceptional and duly justified circumstances, a CSIRT may decide to postpone sharing information with other CSIRTs on cybersecurity-related grounds. The European Commission addressed this issue in a delegated act adopted on December 11, 2025, which further specifies the terms and conditions for invoking those cybersecurity-related grounds. These include situations where immediate dissemination could itself create security concerns or where there are concerns about the ability to ensure the confidentiality of the notified information.

On July 27, 2026, the European Commission published guidance on the CRA to assist organizations in complying with the mandatory cybersecurity requirements for products with digital elements and the related reporting obligations. For further information, read our previous blog post on the European Commission’s guidance on the Cyber Resilience Act.

Read the press release.

Read ENISA’s press release for the SRP.