The EU's Cyber Resilience Act Starts Biting Today. Here's What Developers Need to Know
Mark today in the calendar. As of 11 September 2026, the first real obligations under the EU's Cyber Resilience Act (CRA) are in force, and if you build software or connected hardware that's sold in Europe, there's a good chance they apply to you.
What's changed?
Manufacturers of "products with digital elements", a label that covers a huge range of hardware and software, now have to report two things: actively exploited vulnerabilities in their products, and severe incidents that affect their security.
The deadlines are tight:
- 24 hours for an early warning, counted from the moment you become aware.
- 72 hours for a fuller notification, including what you're doing about it.
- 14 days for a final report once a fix is available (for vulnerabilities), or **one month** for severe incidents.
Law firm Freshfields points out that the clock doesn't stop for weekends or bank holidays. A zero-day discovered on a Friday evening is very much a Saturday evening problem.
It's not just new products
This is the part catching people out. The reporting duty covers products already on the EU market, not just the things you ship from today. That router firmware from a few years back, or the desktop app you released in 2023? If it's still available, it's in scope.
The rest of the CRA, including the security-by-design requirements and software bills of materials (SBOMs), won't fully apply until 11 December 2027. But reporting comes first, and it comes now.
One portal, launching on day one
All reports go through ENISA's new Single Reporting Platform. You file once, it lands with the relevant national CSIRT (the country's computer security incident response team), and ENISA sees it at the same time.
The slightly nerve-wracking detail is that the platform was scheduled to go live on the very same day the obligation kicks in, and as of late August it still wasn't public. It also won't have an API at launch, so reports have to go through the web portal by hand. Anyone hoping to wire this straight into their security tooling will have to wait.
Who's exempt?
Non-commercial open source is the main exception, along with products already covered by their own sector rules, such as medical devices and vehicles. If you're a hobbyist maintaining a library on GitHub, you're very likely fine. If you're a company shipping that same library inside a paid product, you're not.
And for our UK readers: if you sell into the EU, this applies to you. Brexit doesn't get you out of it.
The penalties
Get it wrong and fines can reach €15 million or 2.5% of worldwide annual turnover, whichever is higher. Not the kind of number you want to meet by accident.
What to do this week
Work out which of your products are in scope. Figure out which national CSIRT you'd report to. Make sure a real person owns the process, ideally someone whose phone is on at weekends. And if you don't already know what's inside your software, start building an SBOM. You can't report a vulnerability in a component you didn't know you were using.
As this week's Chrome zero-days showed, actively exploited bugs aren't some rare event. The 24-hour clock is now very real.
