EU Cyber Resilience Act imposes strict vulnerability reporting deadlines on software vendors

Starting September 11, 2026, the EU Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities to ENISA within 24 hours and provide a fuller report within 72 hours. The article highlights the challenges for open-source maintainers and enterprises in tracking exactly what software shipped and when vulnerabilities were discovered. The engineering requirements of the law will not apply until December 2027, creating a gap between reporting and compliance.
The initial reporting mandate takes effect in September 2026, while the technical construction standards are deferred until late 2027, leaving a fifteen-month interval. ActiveState's CEO Abby Kearns noted this interim period functions chiefly as a disclosure obligation rather than a security enforcement measure.
Maintaining an accurate, up-to-date inventory of software components is a core requirement, contrasting with earlier US federal mandates that often produced one-time, quickly outdated documents. Because the vast majority of applications incorporate open-source elements, this tracking burden will affect nearly all EU-facing manufacturers.
The strict 24-hour reporting window could disproportionately strain smaller vendors and volunteer open-source maintainers, who may lack the resources to rapidly assess and report vulnerabilities. This pressure might lead to premature or incomplete disclosures, potentially causing public alarm. Conversely, the extended gap before engineering standards apply may mean that for over a year, companies are required to report problems without yet being compelled to fix systemic design flaws, potentially leaving consumers exposed to known risks during that transition.