EU Cyber Resilience Act's 24-hour clock started on 11 September
From 11 September 2026, Article 14 of the EU Cyber Resilience Act applies: manufacturers of software and devices sold in the EU must report actively exploited vulnerabilities to ENISA—early warning within 24 hours, notification within 72 hours, and final report within 14 days after a fix. Other CRA requirements (SBOM, CE marking, 5-year support) take effect on 11 December 2027.
- Early warning to ENISA within 24 hours of exploitation detection
- Vulnerability notification within 72 hours, final report 14 days after fix
- Rule applies to any developer selling software in EU, including indie games on Steam
- SBOM, CE marking, and 5-year support start on 11 December 2027
Read next
Policy