
What the document says
Regulation (EU) 2024/2847, the Cyber Resilience Act, was adopted on 23 October 2024 and entered into force on 10 December 2024, per its text in the Official Journal. It sets essential cybersecurity requirements for hardware and software products with digital elements sold in the EU, requiring them to be designed and shipped without known exploitable vulnerabilities and to receive security updates, for a minimum support period, throughout a defined product lifetime. The regulation applies in stages rather than all at once. The European Commission's policy page records that manufacturer reporting obligations began applying from 11 September 2026, five days before this entry was prepared, while the regulation's remaining obligations become fully applicable on 11 December 2027.
From 11 September 2026, manufacturers and open-source software stewards must notify actively exploited vulnerabilities and severe incidents affecting their products. ENISA's own description of its new Single Reporting Platform confirms that this channel became operational on that date so that a single notification can reach the relevant national authorities across the EU. The regulation also creates a distinct, lighter regime for open-source stewards, organisations that provide sustained maintenance for free software used commercially, rather than treating them identically to commercial manufacturers.
Confidence and limits
The staged dates and the existence of the reporting platform are established by the regulation's text and by ENISA's own page describing the platform it operates. This entry does not confirm the precise procedural reporting deadline manufacturers face once a notifiable event occurs, since that level of detail sits in implementing guidance beyond what was reviewed here, and it does not evaluate whether any manufacturer has actually used the platform.
Why it mattered
Software security requirements have historically been contractual matters between buyer and seller, enforced unevenly if at all. The Cyber Resilience Act instead makes baseline security a market-access condition, similar to product safety law for physical goods, and adds a reporting duty that runs regardless of contract terms. Because the obligations phase in over three years, 11 September 2026 is a meaningful marker: it is the first date on which a manufacturer's silence about an actively exploited flaw in its own product can itself become a regulatory matter, well before the rest of the regulation takes full effect.
Defensive takeaway
Confirm who inside your organisation owns the obligation to report an actively exploited vulnerability to ENISA's Single Reporting Platform, and check that this responsibility does not currently sit undefined between your security and legal teams.
- Does your product qualify as one with digital elements placed on the EU market, and if so, do you know your applicable support period?
- Who in your organisation is responsible for filing a notification if one of your products has an actively exploited vulnerability?
- If you maintain open-source software used commercially, have you determined whether the regulation's steward provisions apply to your project?
The Cyber Resilience Act's staged timetable means its full effect will not be visible until December 2027, but the reporting duty that began in September 2026 already changes what silence about a known, exploited flaw can cost a manufacturer inside the EU market.
If you make or integrate products with digital elements for the EU market, confirm whether your team can meet the notification duty to ENISA's Single Reporting Platform for actively exploited vulnerabilities, since that obligation is already in force.
EUR-Lex and the European Commission and ENISA's own pages confirm the regulation's staged dates and the vulnerability-reporting channel now open. This entry does not assess any manufacturer's actual compliance.
Sources & reading trail
Adoption date, secure-by-design and vulnerability-handling requirements, and the light-touch open-source steward regime.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Entry into force on 10 December 2024 and the staged dates for reporting obligations and full application.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Confirms the reporting platform became operational on 11 September 2026 for actively exploited vulnerabilities and severe incidents.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.