Skip to content
TECH CEO Daily

EU Cyber Resilience Act reporting now live with 24-hour clock for exploited flaws

Hardware and software makers selling in the EU must now warn authorities within 24 hours of learning a product flaw is being exploited, including for older products.

· 3 min read

The 60-second brief

  • 1Since September 11, manufacturers must send an early warning within 24 hours of learning a product flaw is actively exploited.
  • 2Reports go through ENISA's new Single Reporting Platform and cover products already on the market before the rules.
  • 3Manufacturers must also inform affected users, which pulls product, legal and communications teams into incident response.
Early warning deadline
24 hours
Full notification deadline
72 hours
Final report, vulnerabilities
14 days after a fix is available
Main CRA obligations apply
Dec 11, 2027

Why CEOs should care

For boards of companies that sell connected devices or software into Europe, this is now a live compliance duty with a clock measured in hours. Ask management who decides that a flaw is actively exploited, who files the early warning, and whether that process works on a weekend. Law firm Crowell & Moring's checklist starts with basics: identifying the EU main establishment, setting up platform accounts with multifactor authentication, and designating primary and backup authorized representatives.

For CISOs and product security leaders, the trigger is awareness, which Hogan Lovells Cadwalader describes as a reasonable degree of certainty that a flaw is being exploited. That links product security to threat intelligence: reports from customers, researchers or government catalogs may start the clock. Build a documented reportability assessment, templates for the 24-hour and 72-hour filings, and a log of decisions. Crowell & Moring also advises adding vulnerability disclosure terms to supplier contracts, since a component maker's flaw can become your report.

For general counsel and communications chiefs, user notification is the part that reaches customers. Coordinate CRA filings with parallel duties under the NIS2 directive and GDPR so one incident does not produce three inconsistent stories.

Spotted an error? Request a correction. Read our editorial standards and AI policy.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Weekdays, 6 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.

Hussein MukhtarWritten by
About the author

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

At Tech CEO Daily, Hussein covers the companies, founders, technologies, and market shifts shaping the modern business world. His writing focuses on translating complex developments into clear, practical insights for entrepreneurs, executives, investors, and technology professionals.

With a strong interest in emerging technology and business strategy, Hussein follows developments across AI, SaaS, fintech, cybersecurity, startups, and the global technology economy.

His goal is simple: help readers understand not only what is happening in technology, but why it matters for business.