{"id":2017,"date":"2026-09-13T13:05:00","date_gmt":"2026-09-13T04:05:00","guid":{"rendered":"https:\/\/onepress.co.kr\/index.php\/briefing\/2026-09-13-eu-cra-reporting-start-en\/"},"modified":"2026-09-13T13:05:00","modified_gmt":"2026-09-13T04:05:00","slug":"2026-09-13-eu-cra-reporting-start-en","status":"publish","type":"briefing","link":"https:\/\/onepress.co.kr\/index.php\/briefing\/2026-09-13-eu-cra-reporting-start-en\/","title":{"rendered":"EU digital-product security incidents now require an initial warning within 24 hours"},"content":{"rendered":"<p><strong>2026-09-13 13:05 KST<\/strong><\/p>\n<p>The Cyber Resilience Act reporting duties began on 11 September 2026. Manufacturers supplying hardware or software to the EU market must send an early warning within 24 hours of becoming aware of an actively exploited vulnerability or a severe incident affecting product security.<\/p>\n<p>The scope can include smartwatches, smart locks, baby monitors and apps. But the Act\u2019s main design, updating and CE-marking obligations apply from 11 December 2027, so this is not the full law taking effect at once.<\/p>\n<h2>What must be reported?<\/h2>\n<p>A flaw is not automatically reportable merely because it exists. The duty covers vulnerabilities backed by reliable evidence of unauthorized active exploitation, and incidents that seriously affect or can affect the availability, authenticity, integrity or confidentiality of product data or functions.<\/p>\n<h2>What is the timetable?<\/h2>\n<p>An early warning is due within 24 hours of awareness, followed by a fuller notification within 72 hours. The final report is due within 14 days after a fix or mitigation becomes available for an exploited vulnerability, and within one month for a severe incident.<\/p>\n<figure class=\"wp-block-image size-full\"><img decoding=\"async\" src=\"https:\/\/onepress.co.kr\/wp-content\/uploads\/2026\/09\/eu-cra-reporting-start-en.png\" alt=\"EU digital-product security incidents now require an initial warning within 24 hours\" loading=\"lazy\" \/><figcaption class=\"op-briefing-image-caption\">This AI-generated image explains the topic; it is not a photograph of the actual place or event.<\/figcaption><\/figure>\n<h2>Who reports where?<\/h2>\n<p>Manufacturers use the single platform operated by the EU cybersecurity agency ENISA, which routes relevant information to national response teams and authorities. Products already on the EU market can be covered, but exploitation already known before 11 September is not reported retrospectively.<\/p>\n<h2>Is all open-source software treated alike?<\/h2>\n<p>Free and open-source software developed outside commercial activity should not be read as an ordinary manufactured product. ENISA says the separate reporting duties for open-source software stewards apply from 11 December 2027.<\/p>\n<h2>What changes for consumers?<\/h2>\n<p>This does not promise an individual consumer notice within 24 hours. It accelerates reporting between makers and authorities. Updates and user alerts depend on the incident, so people should still follow vendor security notices and install device updates.<\/p>\n<h2>Primary sources and independent checks<\/h2>\n<p><a href=\"https:\/\/commission.europa.eu\/news-and-media\/news\/safer-and-more-secure-digital-products-2026-09-11_en\" target=\"_blank\" rel=\"noopener noreferrer\">\uc720\ub7fd\uc5f0\ud569 \uc9d1\ud589\uc704\uc6d0\ud68c \uc2dc\ud589 \uc548\ub0b4<\/a><\/p>\n<p><a href=\"https:\/\/www.enisa.europa.eu\/topics\/product-security\/single-reporting-platform-srp\/frequently-asked-questions\" target=\"_blank\" rel=\"noopener noreferrer\">ENISA \ub2e8\uc77c \uc2e0\uace0 \ud50c\ub7ab\ud3fc FAQ<\/a><\/p>\n<p><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/EN\/TXT\/?uri=legissum%3A4797302\" target=\"_blank\" rel=\"noopener noreferrer\">EUR-Lex \uc0ac\uc774\ubc84 \ubcf5\uc6d0\ub825\ubc95 \uc694\uc57d<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Manufacturers placing digital products on the EU market must issue an early warning within 24 hours after learning of an actively exploited vulnerability or severe security incident. The Cyber Resilience Act is not yet fully applicable.<\/p>\n","protected":false},"featured_media":0,"template":"","meta":[],"class_list":["post-2017","briefing","type-briefing","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/briefing\/2017","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/briefing"}],"about":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/types\/briefing"}],"wp:attachment":[{"href":"https:\/\/onepress.co.kr\/index.php\/wp-json\/wp\/v2\/media?parent=2017"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}