From books

From 11 September 2026, any product with digital elements sold in the Union carries reporting duties for actively exploited vulnerabilities, with a 24-hour clock running.

Parlamentul European și Consiliul Uniunii Europene · Regulamentul (UE) 2024/2847 privind cerințe orizontale de securitate cibernetică pentru produsele cu elemente digitale · 2024 · Regulamentul (UE) 2024/2847 (actul privind reziliența cibernetică), art. 13 alin. (1) — obligațiile fabricantului2 minutes readpublic domain
When placing a product with digital elements on the market, manufacturers shall ensure that it has been designed, developed and produced in accordance with the essential cybersecurity requirements set out in Part I of Annex I.Parlamentul European și Consiliul Uniunii Europene · Regulamentul (UE) 2024/2847 privind cerințe orizontale de securitate cibernetică pentru produsele cu elemente digitale · 2024 · Regulamentul (UE) 2024/2847 (actul privind reziliența cibernetică), art. 13 alin. (1) — obligațiile fabricantului

From 11 September 2026, the 24-hour clock starts the moment the manufacturer learns of an actively exploited vulnerability.

Regulation (EU) 2024/2847, the cyber resilience act for short, moves liability onto the manufacturer: the product must be designed, developed and produced against the essential requirements of Part I of Annex I, and the risk is assessed and documented across the whole support period. In practice that means shipping with no known exploitable vulnerabilities, secure default configuration, security updates and a software bill of materials covering top-level dependencies. The calendar is tiered. The reporting duties of Article 14 apply from 11 September 2026: an actively exploited vulnerability is announced by an early warning within 24 hours, a notification within 72 hours and a final report within 14 days. The rest of the regulation applies from 11 December 2027. For anyone who already holds a certified system, the secure development controls of Annex A, 8.25-8.28, from the secure life cycle to secure coding, are exactly where to start.

Why it mattersThe 24-hour deadline is not negotiated during the incident: either a vulnerability handling process exists that can meet it, or it does not.

ProductwithEssentialrequirements,Activelyexploited24 hours /72 hours /
The duty starts at design and closes at reporting.

Back to the feed