← Back to events
ActiveTech

EU CYBER RESILIENCE ACT forces manufacturers to disclose exploited vulnerabilit

What happened

As of 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents impacting the security of products with digital elements. In accordance with Article 71(2) of the CRA, open-source software stewards are subject to reporting obligations (Article 24(3)) from 11 December 2027.

Summary assembled by rule from the sources below

Why it's spreading

Sources