chiprook
← Policy
PolicyOctober 9, 2026, 02:00

EU's Cyber Resilience Act Article 14 kicks in: 24-hour clock for exploited vulnerabilities

Since 11 September 2026, Article 14 of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers to report actively exploited vulnerabilities and severe incidents. Deadlines are 24 hours for an early warning, 72 hours for a fuller notification and 14 days for a final report; penalties of up to €15 million or 2.5% of turnover only arrive in December 2027.

EU's Cyber Resilience Act Article 14 kicks in: 24-hour clock for exploited vulnerabilities
#EU#ENISA
Read next
Policy

Cyber Resilience Act: manufacturers must report exploited flaws within 24 hours

Policy

EU Cyber Resilience Act sets cybersecurity rules for containers and Kubernetes

Policy

EU Cyber Resilience Act: Irish software firms face fines up to €15m

Security

Pentagon orders Cyber Command to act after suicide deaths