Global connected devices IoT security regulation

The EU's 24-Hour Cyber Resilience Act Reporting Clock Is Defensible, but Its Penalty Design Needs Restraint

Since 11 September 2026, makers of connected products must report exploited vulnerabilities within 24 hours. The rule is sound, but enforcement should favour fixes over fines.

EU Cyber Resilience Act reporting rules People of Internet Research · Global 24 hours Early warning deadline From awareness of an actively expl… 72 hours Full notification deadline Second stage of the reporting cloc… €15M / 2.5% Maximum fine ceiling Whichever is higher, for breaches … Dec 2027 Full application date Secure-by-default design and CE ma… peopleofinternet.com
EU Cyber Resilience Act reporting rule… People of Internet Research · Global 24 hours Early warning deadline 72 hours Full notification deadline €15M / 2.5% Maximum fine ceiling Dec 2027 Full application date peopleofinternet.com

Key Takeaways

What changed on 11 September

On 11 September 2026, the first binding obligations of the EU Cyber Resilience Act (Regulation (EU) 2024/2847) took effect. Manufacturers of products with digital elements, a category that covers everything from smart doorbells to routers and standalone software, must now report two kinds of events. The first is an actively exploited vulnerability. The second is a severe incident affecting the product's security. The Commission's CRA reporting page sets out a three-stage clock. An early warning is due within 24 hours of the manufacturer becoming aware, and a fuller notification within 72 hours. A final report follows 14 days after a fix is available for vulnerabilities, or within a month of the incident notification for severe incidents.

The rest of the regulation, including secure-by-default design, security update duties and CE marking, applies from 11 December 2027, according to the Commission's CRA policy page. Reporting therefore runs about 15 months ahead of the product-design rules.

The strongest case for the rule

The case for early reporting is serious and deserves a fair statement. Connected devices are sold worldwide, are rarely patched by their owners, and are often the entry point for botnets and intrusions. When a vulnerability is being exploited in the wild, the interval between first exploitation and regulator awareness is exactly when defenders are blind. A single, mandatory channel means a national response team can warn other member states' teams and users before an attack spreads. Voluntary disclosure has worked for well-run vendors. It has not worked for the long tail of low-margin hardware makers who have no incentive to say anything.

The design also has features that a pro-innovation reading should credit. Under Article 14 of the regulation, as published on EUR-Lex, a manufacturer reports once, through ENISA's Single Reporting Platform. The notification goes to the national response team (CSIRT) where the manufacturer has its main establishment, and ENISA sees it at the same time. That avoids a patchwork of 27 separate filings. Disclosure to other national teams can also be delayed on justified cybersecurity grounds, which protects users from a vulnerability being broadcast before a patch exists.

Where the design deserves scrutiny

The clock starts at awareness, and the scope is broad. The 24-hour early warning is triggered when a manufacturer becomes aware of active exploitation. That is workable for a company with a security team on call. It is harder for a small firm whose entire engineering staff is in one time zone. Article 14 also defines a severe incident widely. It covers events that affect, or could affect, the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or that could lead to malicious code running in the product or a user's network. The words 'could affect' invite over-reporting out of caution. Authorities would then receive a flood of low-value filings, which dilutes the signal the system is meant to create.

The penalty ceiling is large. Article 64(2) allows fines of up to EUR 15 million or 2.5% of worldwide annual turnover, whichever is higher, for breaches of the essential requirements and of Articles 13 and 14. The regulation does soften the blow for the smallest players. Article 64(10)(a) exempts microenterprises and small enterprises from fines for missing the early-warning and notification deadlines. That is a sensible carve-out, and it shows the drafters understood the risk. Medium-sized firms and fast-growing startups get no such shelter.

The compliance burden compounds. As McCann FitzGerald notes, the CRA applies extraterritorially to any operator placing covered products on the EU market. Importers and distributors can become 'manufacturers' if they sell under their own name or substantially modify a product. Firms must also reconcile the CRA with notification duties under GDPR and NIS2. A company that ships one device worldwide may now run three clocks for a single event.

What proportionate implementation looks like

The goal of the reporting rule is faster fixes, not a paper trail. Three practices would keep it aligned with that goal.

Open-source projects are the other test. The regulation gives open-source stewards a lighter regime. Article 24 requires a documented, verifiable cybersecurity policy, and the Commission's reporting page says stewards' reporting duties apply only from 11 December 2027. A regime that pushed volunteer maintainers out of the ecosystem would make the connected-device supply chain less secure, not more. The Commission should watch for any such chilling effect over the next year.

The bottom line

A 24-hour early warning for actively exploited flaws is a narrow, defensible duty. It targets a moment when speed matters and when the manufacturer is the only party who knows what is happening. The risk is not the rule itself but how it is enforced. If regulators use the headline penalty ceiling as a first resort, they will push firms toward silence and legal hedging. If they use the reporting data to coordinate fixes, the CRA could become a model that other jurisdictions copy for good reason. The 15 months before the design obligations bite are the time to set that tone.

Sources & Citations

  1. European Commission: CRA reporting obligations
  2. European Commission: Cyber Resilience Act policy page
  3. Regulation (EU) 2024/2847 on EUR-Lex
  4. McCann FitzGerald: CRA reporting obligations apply from 11 September 2026