The European Union’s Cyber Resilience Act (CRA) is entering its first operational phase, with manufacturers of products with digital elements facing a key compliance deadline on 11 September 2026. From that date, vendors selling software and connected hardware in the EU must report actively exploited vulnerabilities and severe security incidents through an ENISA-operated Single Reporting Platform, including an early warning within 24 hours of becoming aware of an issue and a fuller notification within 72 hours. The reporting duty is limited to cases with reliable evidence of active exploitation or incidents that seriously affect product security, rather than every discovered flaw.
The CRA is the EU’s product-security framework for software and connectable hardware, designed to address weak default security, poor vulnerability handling, and inconsistent delivery of security updates across a product’s lifecycle. It requires manufacturers to build cybersecurity into planning, design, development, and maintenance, with some higher-risk products subject to third-party conformity assessment before sale in the EU and compliance signaled through CE marking. The European Commission has also issued implementation guidance clarifying scope, substantial modifications, support periods, and risk-assessment expectations, ahead of the broader CRA obligations taking effect in December 2027.

See which actors are running it and whether you're in range.
3 events from the most recent confirmed update back to the earliest known activity.
The European Commission published practical guidance to help manufacturers and developers understand how the Cyber Resilience Act will work in practice. The guidance clarified scope, substantial modifications, support periods, reporting expectations, and cybersecurity risk assessment requirements.
Germany's Federal Office for Information Security (BSI) published version 1.0 of technical guideline TR-03183 to help manufacturers interpret and implement the EU Cyber Resilience Act using a risk-based approach. BSI also released an initial set of CRA-related security controls in OSCAL format via GitHub as interim practical guidance ahead of future European standards.
The EU Cyber Resilience Act entered into force, establishing a regulatory framework for cybersecurity requirements for products with digital elements sold in the EU.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourceteiss.co.uk
Open sourcedigital-strategy.ec.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.