Business & compliance
13 September 2026·5 min read
The EU Cyber Resilience Act’s vulnerability-reporting duty is now live — and it may already apply to your software
On September 11, 2026, Article 14 of the EU Cyber Resilience Act took effect: any company that "manufactures" a product with digital elements — hardware or software sold under its own brand — must now report an actively exploited vulnerability within 24 hours and a severe incident within 72 hours, to ENISA and France’s national CSIRT, under fines of up to €15 million or 2.5% of global turnover. A 2024 academic survey found only 12.3% of SMEs were even aware the regulation existed. Here is what actually changed, who it concerns, and where to start.
Read →