UK connected devices IoT security regulation

The EU's 24-Hour Vulnerability Reporting Rule Now Sets the Real Compliance Bar for UK Connected-Device Makers

The Cyber Resilience Act's Article 14 reporting duty, live since Sept 11, binds UK IoT firms harder and faster than UK law itself.

Two Regimes, One UK Manufacturer People of Internet Research · UK 24 hours CRA early warning deadline Time to alert ENISA once a UK-made… €15M / 2.5% Max CRA reporting fine Whichever is higher, for breaches … £10M / 4% Max UK PSTI fixed penalty OPSS's statutory ceiling for PSTI … 0 hours UK PSTI reporting duties PSTI sets no active-exploitation r… peopleofinternet.com
Two Regimes, One UK Manufacturer People of Internet Research · UK 24 hours CRA early warning deadline €15M / 2.5% Max CRA reporting fine £10M / 4% Max UK PSTI fixed penalty 0 hours UK PSTI reporting duties peopleofinternet.com

Key Takeaways

The clock that started in Brussels now runs in Britain too

Since 11 September 2026, any manufacturer placing a "product with digital elements" on the EU market has been legally required to report actively exploited vulnerabilities to the European Union Agency for Cybersecurity (ENISA) within 24 hours of becoming aware of them. This is Article 14 of the Cyber Resilience Act (CRA), and ENISA confirmed the obligation went live alongside its new Single Reporting Platform (SRP), which routes a manufacturer's single filing to the relevant national CSIRT automatically (ENISA). The three-stage clock is unforgiving: a 24-hour early warning, a fuller 72-hour notification with an initial assessment, and a final report within 14 days of a fix becoming available (European Commission).

Crucially, this does not wait for Brexit-style carve-outs. The rule binds "manufacturers of products with digital elements made available in the EU, regardless of where those manufacturers are based" — meaning a smart-lock or router maker in Sheffield selling into Germany or Poland is caught exactly as a firm headquartered in Munich would be (The Register).

The case for a fast, common reporting channel

Before arguing the toll this takes on smaller firms, it's worth being honest about why regulators built it this way. IoT insecurity has a specific, well-documented failure mode: a vulnerability is exploited quietly, spreads across thousands of identical devices (the Mirai botnet remains the reference case), and manufacturers either don't know or sit on the knowledge while drafting a careful press statement. A mandatory, harmonised, fast disclosure channel is a real answer to that — it forces awareness of active exploitation to reach the people who can push out patches or warn users before a vulnerability is weaponised at scale across a 450-million-consumer market. Centralising through one ENISA portal instead of 27 separate national regimes is also, on its own terms, the deregulatory choice: manufacturers file once.

Where it collides with the UK's actual law

The problem is that this is now the operative IoT security standard for UK manufacturers, and it sits well ahead of what Parliament actually legislated. The UK's own regime — the Product Security and Telecommunications Infrastructure Act 2022, in force via the 2023 Regulations since 29 April 2024 — imposes exactly three baseline duties: no default or easily guessable passwords, a published vulnerability-disclosure point of contact, and disclosed minimum security-update periods, aligned to the ETSI EN 303 645 standard (GOV.UK). Notably, PSTI contains no equivalent 24-hour active-exploitation reporting duty at all. A UK manufacturer selling only domestically has no such clock; the same manufacturer selling one device into the EU is bound by one of the tightest incident-reporting deadlines in tech regulation anywhere.

Enforcement philosophy diverges just as sharply. The UK's Office for Product Safety and Standards can impose fixed monetary penalties up to the greater of £10 million or 4% of qualifying worldwide revenue, plus £20,000 per day of continuing non-compliance — but OPSS describes its approach as "risk-based" and weighs harm, culpability and mitigating circumstances before setting an actual figure, not just the statutory ceiling (GOV.UK/OPSS). The CRA's ceiling is comparable — up to €15 million or 2.5% of global turnover, whichever is higher — but reporting failures are treated as breaches of a core obligation, with less of the discretionary calibration OPSS advertises (The Register).

The proportionality problem is real, not hypothetical

A 24-hour window from the moment a firm reaches "reasonable degree of certainty" that exploitation is occurring is a defensible standard for a company with a dedicated security operations centre. It is a genuinely difficult standard for the small and mid-sized UK hardware manufacturers — smart-meter component makers, industrial sensor vendors, connected-appliance firms — who make up much of Britain's IoT export base and do not have in-house EU compliance counsel on retainer. These firms now face two separate regimes with different triggers, different regulators, and no reporting reciprocity: a report filed with ENISA's SRP does nothing to satisfy OPSS, and vice versa. That duplication is pure compliance overhead with no corresponding security benefit — the vulnerability doesn't become more fixed because it was filed twice.

The sensible fix is not weaker EU disclosure rules — fast reporting of live exploitation is one of the better-justified planks of the CRA — but UK regulatory alignment that spares exporters from maintaining two incident-response playbooks for the same product.

What should change

The UK government does not need to import Article 14 wholesale into PSTI to fix this. It should, at minimum, issue explicit DSIT/OPSS guidance mapping CRA reporting duties onto UK obligations for dual-market manufacturers, so a firm that has correctly reported to ENISA isn't left guessing whether it has also discharged any UK-side disclosure expectation. Longer term, given that UK manufacturers exporting into the EU are already bound by the tougher standard as a practical matter, Parliament should consider whether PSTI's narrower scope still reflects the market reality — but any expansion should preserve OPSS's proportionate, risk-based enforcement posture rather than adopt the EU's stricter liability framing wholesale. Regulatory competition should mean choosing the better rule, not paying twice for the stricter one.

Sources & Citations

  1. ENISA — CRA Single Reporting Platform launch
  2. European Commission — CRA reporting obligations
  3. GOV.UK — Consumer connectable product security regulations
  4. GOV.UK/OPSS — PSTI enforcement penalty guidance
  5. The Register — CRA 24-hour vulnerability clock