EU Cyber Resilience Act: Reporting Duty for Exploited Vulnerabilities Starts 11 September 2026
From 11 September 2026, manufacturers must report actively exploited vulnerabilities to ENISA and their CSIRT within 24 hours. What the first CRA deadline means — including for open source.










