EU Cyber Resilience Act Reporting Obligations Take Effect Today
ActiveState
September 11, 2026
FOR IMMEDIATE RELEASE
Requiring Immediate Vulnerability Disclosure Even for Products Already on the Market
VANCOUVER, British Columbia – September 11, 2026 – Today, the vulnerability and incident reporting obligations under Article 14 of the European Union's Cyber Resilience Act (CRA) become enforceable. Manufacturers of products with digital elements sold into the European Union, including companies based outside the EU that sell into that market, must now report actively exploited vulnerabilities and severe incidents within 24 hours of becoming aware of them, and this obligation applies to legacy products already on the market, not just new releases. ActiveState is walking security and engineering leaders through everything that changes today, so they have an action plan in place for the immediate term, ahead of the EU CRA's next major deadline in December 2027. .
Security and engineering teams that have not yet mapped their exposure should start with ActiveState's guide, EU CRA Compliance for Software Manufacturers, which breaks down the Article 14 reporting timeline, who is in scope, and the steps to close the visibility gap before December 2027.
Why This Deadline Lands Before Most Teams Are Ready
Open source software makes up 98% of the applications enterprises run today, and a meaningful share of that footprint arrives through transitive dependencies that no one on the team explicitly chose. Most organizations still cannot answer what open source components are in a given product, when a flaw in one of them was discovered, or how long remediation actually took. That gap matters more today than it did yesterday: the industry average time to remediate a critical vulnerability still runs around 54 days (Edgescan, 2026), while the EU CRA now gives manufacturers 24 hours to report an actively exploited flaw once they know about it. A scanner report sitting in a dashboard is not a compliance answer. A defined, auditable process is.
"For years, 'we had a scanner' was treated as a defensible security posture. As of today, it is not a legal one," said Abby Kearns, CEO of ActiveState. "The EU CRA does not care whether the vulnerable component shipped last month or five years ago. If it is in a product on the EU market, the clock is running the moment you know about it. Security and engineering leaders need to treat today as the deadline it is, not a warm-up for 2027."
What Takes Effect on September 11, 2026
Article 14 introduces a staged reporting sequence that manufacturers must follow the moment they become aware of an actively exploited vulnerability or a severe incident affecting a product with digital elements:
- 24 hours: An early warning to the European Union Agency for Cybersecurity (ENISA) and the relevant national CSIRT, submitted through ENISA's Single Reporting Platform.
- 72 hours: A full notification detailing the vulnerability or incident and any corrective or mitigating measures already taken.
- 14 days or 30 days: A final report, due within 14 days of a fix becoming available for an actively exploited vulnerability, or within 30 days for a severe incident.
This obligation covers manufacturers established in the EU and manufacturers outside the EU that place products with digital elements on the EU market. It also reaches vulnerabilities in upstream open source components embedded in a product, so a flaw in a dependency a team did not write still triggers the manufacturer's reporting duty. Non-compliance sits in the CRA's highest penalty tier, with fines reported at up to €15 million or 2.5% of global annual turnover, whichever is greater. Companies can read the full details of the regulation at the official website of the European Union.
Immediate Actions for Security and Engineering Teams
Companies do not need to wait for the December 2027 compliance deadline to start closing this gap. ActiveState recommends prioritizing the following now:
- Build real component visibility. A current, accurate software bill of materials (SBOM) covering direct and transitive open source components is the foundation for answering what was in a product and when a flaw entered it.
- Wire inventories to vulnerability data. Component lists need to be connected to vulnerability feeds so an actively exploited flaw surfaces immediately, not weeks later during a routine scan.
- Pre-assign the reporting workflow. Decide now who drafts a report, who approves it, and who submits it, and register with the ENISA platform before an incident forces the question.
- Align with existing incident response. Fold the EU CRA's 24-hour and 72-hour clocks into whatever process already exists for NIS2 or GDPR incident reporting, rather than building a separate one.
- Push obligations upstream. Add contract language requiring suppliers and component providers to notify your team fast enough to meet your own 24-hour window.
"The question we hear from security leaders is simple: what was in our product, when did we know, what did we do, and how long did it take," said Jacqueline Winter, CFO and CISO of ActiveState. "If you cannot answer that today for every product on the EU market, that is the gap to close first. This has to be a defined process that survives an audit, not a practice that depends on one person's memory. That is exactly what a governed open source catalog with built-in provenance and a remediation SLA, five business days for critical CVEs once an upstream fix exists, is built to support."
The Next Deadline: December 11, 2027
Today's reporting obligations are the first enforceable milestone under the CRA, not the last. The full set of CE-marking and product security requirements comes due on December 11, 2027, when manufacturers must demonstrate complete conformity across their EU product portfolios. The visibility and documentation work required to meet today's 24-hour reporting window, accurate SBOMs, tracked remediation timelines, and an auditable vulnerability handling process, is the same foundation the 2027 deadline will require at a larger scale. Teams that treat today's deadline as a rehearsal for 2027, rather than a one-time compliance task, will be in a materially stronger position when the full regulation takes hold.
About ActiveState
ActiveState is the trusted source for secure open source software. For nearly 30 years we have worked in the software development lifecycle; today we give security and engineering leaders a secure foundation for the open source their teams depend on. By building every component from source within SLSA Level 3 infrastructure and continuously remediating vulnerabilities against guaranteed SLAs, we provide the provenance and documented due diligence needed to manage open source risk, whether code is written by a human or generated by an AI agent. Learn more at activestate.com.
Media Contact
Brandy Coulsey
Brand and Communications Manager, ActiveState
brandyc@activestate.com


