MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-08 · via BleepingComputer

EU Cyber Resilience Act imposes strict vulnerability reporting deadlines on software vendors

Image via BleepingComputer
Image via BleepingComputer

Starting September 11, 2026, the EU Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities to ENISA within 24 hours and provide a fuller report within 72 hours. The article highlights the challenges for open-source maintainers and enterprises in tracking exactly what software shipped and when vulnerabilities were discovered. The engineering requirements of the law will not apply until December 2027, creating a gap between reporting and compliance.

Expanded Detail

The initial reporting mandate takes effect in September 2026, while the technical construction standards are deferred until late 2027, leaving a fifteen-month interval. ActiveState's CEO Abby Kearns noted this interim period functions chiefly as a disclosure obligation rather than a security enforcement measure.

Maintaining an accurate, up-to-date inventory of software components is a core requirement, contrasting with earlier US federal mandates that often produced one-time, quickly outdated documents. Because the vast majority of applications incorporate open-source elements, this tracking burden will affect nearly all EU-facing manufacturers.

Context

The strict 24-hour reporting window could disproportionately strain smaller vendors and volunteer open-source maintainers, who may lack the resources to rapidly assess and report vulnerabilities. This pressure might lead to premature or incomplete disclosures, potentially causing public alarm. Conversely, the extended gap before engineering standards apply may mean that for over a year, companies are required to report problems without yet being compelled to fix systemic design flaws, potentially leaving consumers exposed to known risks during that transition.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Researcher Earns Bounty for Chrome Zero-Day Fix · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “The EU CRA's Real Question: What Shipped, and When Did You Know?.” Browse more stories.