chiprook
← Policy
PolicySeptember 17, 2026, 17:41

EU Cyber Resilience Act's 24-hour clock started on 11 September

From 11 September 2026, Article 14 of the EU Cyber Resilience Act applies: manufacturers of software and devices sold in the EU must report actively exploited vulnerabilities to ENISA—early warning within 24 hours, notification within 72 hours, and final report within 14 days after a fix. Other CRA requirements (SBOM, CE marking, 5-year support) take effect on 11 December 2027.

EU Cyber Resilience Act's 24-hour clock started on 11 September
#ENISA
Read next
Policy

Tesla FSD Supervised approved in Czechia, the seventh EU country

Policy

Hong Kong and Singapore expand facial recognition at borders

Policy

UK Court Challenges Secrecy Over Apple iCloud Backdoor Order

Policy

Trump rejects AI slowdown calls, launches "AI Force"