Businesses operating within the European Union must now notify authorities of serious product security incidents within 24 hours or face massive financial penalties under the new Cyber Resilience Act.
- Mandatory 24-hour window to report actively exploited vulnerabilities.
- Potential fines of up to €15 million or 2.5% of total global annual turnover.
- Exemptions provided for micro and small enterprises regarding reporting deadlines.
- Applicable to all network-connected products sold within the EU market.
The European Union (EU) has accelerated the implementation of a critical component of the Cyber Resilience Act (CRA). While the bulk of the regulation's requirements—such as Software Bills of Materials (SBOMs) and formal risk assessments—won't be strictly enforced until December 2027, the EU has fast-tracked the reporting obligations to combat the rising tide of cyber threats.
Effective immediately, any organization distributing network-connected hardware or software in EU member states must report actively exploited vulnerabilities or severe security incidents to the European Union Agency for Cybersecurity (ENISA) within a strict 24-hour window. This is followed by a requirement to provide a comprehensive notification within 72 hours, detailing the impact and mitigation steps for users.
Why This Matters
BozokMedia analysis shows that this regulatory pivot effectively ends the era of 'security by obscurity' for many vendors. By mandating near-instant disclosure, the EU is forcing a systemic shift toward transparency. This creates a high-stakes environment where a company's internal incident response speed directly correlates with its legal and financial liability.
"The maximum penalties are sending the right message, however... the majority of fines were nowhere near the maximum amounts mentioned in the regulation." - Dr. Aram Hovsepyan, CEO of Codific.
The scope of the CRA is expansive. It does not matter if a company is headquartered in the US, Asia, or elsewhere; if the product is sold in the EU and has network connectivity, the law applies. The only major exceptions are open-source software and specific technologies already covered by other EU regulations.
To avoid stifling innovation among smaller players, the EU has carved out exemptions for microenterprises (under 10 employees) and small enterprises (under 50 employees). These entities may not face fines for missing the 24-hour window, and their conformity assessments will be handled in a proportionate manner. Large corporations, however, face the full weight of the law.
| Feature | Large Organizations | Micro/Small Enterprises |
|---|---|---|
| Reporting Deadline | Strict 24 Hours | Flexible/Exempted |
| Max Penalty | €15M or 2.5% Global Revenue | Proportionate Fines |
| Compliance Rigor | High/Full Enforcement | Adjusted/Proportionate |
Frequently Asked Questions
Q1: Does this apply to companies based outside the European Union?
Yes, if the company sells products that are distributed within the EU market, they must comply regardless of their physical location.
Q2: How are these incidents reported to the government?
Reports must be submitted through ENISA's Single Reporting Platform (SRP).