The EU Cyber Resilience Act’s First Deadline Is About Vulnerability Reporting

The EU Cyber Resilience Act’s vulnerability-reporting obligations begin September 11, 2026, after the Commission published practical guidance for manufacturers and software developers.

By THEYDIDNTASK
Security laws often arrive as distant compliance projects. The EU Cyber Resilience Act has a nearer operational checkpoint: vulnerability-reporting obligations begin on September 11, 2026. The European Commission says the Act’s main obligations apply from December 11, 2027, but reporting starts earlier. On July 27, 2026, the Commission published practical guidance to help manufacturers, developers, and businesses understand how to prepare. The Act matters beyond European offices. Software and connected products move across borders, and supply chains rarely stop at the market where a vulnerability was first reported. What the Act covers The Cyber Resilience Act applies to products with digital elements, a broad category that includes connected hardware and software. The Commission’s examples range from baby monitors and smart watches to apps and computer programs. The goal is to address two familiar failures: products shipped with inadequate security and vulnerabilities that do not receive timely updates. The Act introduces mandatory cybersecurity requirements for manufacturers across planning, design, development, and maintenance. That lifecycle framing matters. Security is not treated as a one-time feature that can be checked at launch and forgotten. Manufacturers are expected to handle vulnerabilities during the product’s useful life, while national market-surveillance authorities help enforce the rules. Why September comes before the main deadline The September 11, 2026 date is the start of reporting obligations. It arrives more than a year before the Act’s main requirements, which begin in December 2027. That sequencing gives regulators and companies an earlier test of whether vulnerability information can move through the right channels. A company may have a secure product-development process and still fail if it cannot identify the responsible contact, assess a reported flaw, coordinate a fix, or communicate remediation clearly. The Commission’s July guidance is therefore practical rather than cosmetic. Manufacturers need to understand which products fall within scope, which role they occupy in the supply chain, how a vulnerability is handled, and what evidence demonstrates that the process works. The product is also the update system A device’s security depends on more than its code at release. It depends on whether updates can be delivered, whether users can tell that an update is needed, whether unsupported versions are identified, and whether a vendor maintains a useful vulnerability disclosure channel. For consumers, a CE mark will signal compliance with the Act’s requirements once the applicable obligations begin, but no mark can replace basic questions about support. How long will the product receive updates? How are security notices published? Can the device continue to function safely when a vendor ends support? For developers, the same questions become release engineering work: maintain a software inventory, track dependencies, document vulnerability decisions, and make update paths testable before an incident forces the issue. What smaller teams can do now Teams that sell or maintain connected products can use the early deadline to: Inventory products, dependencies, third-party components, and support commitments. Assign a clear owner for vulnerability intake and regulatory reporting. Test the path from a researcher report to triage, patching, customer notice, and evidence retention. Document how security updates reach users and what happens to unsupported versions. Review the Commission’s guidance and the final legal text with qualified counsel where the product’s scope is uncertain. The Act’s first deadline is a useful correction to the idea that cybersecurity is only a technical problem. A vulnerability report is also a governance event: someone must receive it, understand it, act on it, and explain what happens next.