“When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I.”Parlamentul European și Consiliul Uniunii Europene · Regulamentul (UE) 2024/2847 privind cerințe orizontale de securitate cibernetică pentru produsele cu elemente digitale · 2024 · Regulamentul (UE) 2024/2847 (actul privind reziliența cibernetică), art. 13 alin. (1) — obligațiile fabricantului
From 11 September 2026, the 24-hour clock starts the moment the manufacturer learns of an actively exploited vulnerability.
Regulation (EU) 2024/2847, the cyber resilience act for short, moves liability onto the manufacturer: the product must be designed, developed and produced against the essential requirements of Part I of Annex I, and the risk is assessed and documented across the whole support period. In practice that means shipping with no known exploitable vulnerabilities, secure default configuration, security updates and a software bill of materials covering top-level dependencies. The calendar is tiered. The reporting duties of Article 14 apply from 11 September 2026: an actively exploited vulnerability is announced by an early warning within 24 hours, a notification within 72 hours and a final report within 14 days. The rest of the regulation applies from 11 December 2027. For anyone who already holds a certified system, the secure development controls of Annex A, 8.25-8.28, from the secure life cycle to secure coding, are exactly where to start.
Why it matters The 24-hour deadline is not negotiated during the incident: either a vulnerability handling process exists that can meet it, or it does not.