A security vulnerability in your software? From September, you have 24 hours to report it

SECURITY

Do you develop apps, sell software or make internet-connected devices? Then the Cyber Resilience Act, the EU's new cybersecurity rules for digital products, may apply to you. Its first obligation took effect on 11 September 2026, yet many businesses are still unaware of it.

What is the Cyber Resilience Act?

This EU regulation introduces mandatory cybersecurity requirements for products with digital elements, covering both software and hardware. Like the AI Act, it applies directly across the EU.

The principle is straightforward: responsibility for a product's security belongs to the business placing it on the market, rather than the customer who buys it. Too many products are inadequately protected and do not receive security updates promptly. The regulation aims to change that.

Who does it affect?

It applies to manufacturers of products that contain software or connect to other devices or networks. Examples include:

  • mobile and desktop applications;
  • software you sell or license;
  • smart devices, routers, cameras and internet-connected toys.

If you develop a bespoke product for a client, agree with them which party will be considered the manufacturer.

What applies from 11 September 2026?

Manufacturers must report two types of issue:

Actively exploited vulnerabilities. If you learn that an attacker has actually exploited a vulnerability in your product, you must report it.

Severe security incidents. These are incidents that compromise the security of your product.

The deadlines are tight: an early warning is due within 24 hours of becoming aware of the issue, followed by a more detailed notification within 72 hours. Reports are submitted through a single EU platform.

One detail matters: the reporting obligation also covers products already on the market. Even older software that you are merely maintaining needs to be monitored.

What changes in December 2027?

Most of the requirements will apply from 11 December 2027. At that point, reporting vulnerabilities will no longer be enough. Products will need security built into their design, ongoing security updates and compliance with CE marking requirements. That may seem a long way off, but product development cycles can make the deadline arrive quickly.

What are the consequences?

A manufacturer that fails to comply with its reporting obligations could face a fine of up to €15 million or 2.5% of its worldwide annual turnover. In more serious cases, sales of the product in the EU may be restricted.

What should you check now?

Identify which of your products fall within the new rules, including older versions that customers still use. Decide who in your company is responsible for reporting incidents and how they will be alerted, including at weekends. Put together a simple procedure for the first 24 hours. Then start planning how your products will meet the requirements that apply from December 2027.

Want to stay up to date?

The Cyber Resilience Act is another sign of how quickly the rules governing digital products are changing. On our blog, we explain these developments without unnecessary legal jargon. We cover AI, software development, business and the issues we are working through at Codium.

NEWSLETTER

Stay a step ahead

New articles, guides and dev updates. Once a month, no spam.

Cookie Settings

Choose which categories of cookies you'd like to allow. Necessary cookies are required for the site to function and can't be turned off.

Meet us at SBCarrow_forward