EU Cyber Resilience Act's Reporting Clock Starts September 11: Do You Know What You Shipped?
The EU Cyber Resilience Act's (CRA) vulnerability reporting requirements take effect on September 11, according to BleepingComputer, which cites an ActiveState analysis of the new rules. Under the CRA, software vendors will have as little as 24 hours to report actively exploited vulnerabilities to authorities.
Why It Matters for Defenders
This is a compliance deadline, not a new vulnerability or exploit, but it has direct operational consequences for any organization that develops or distributes software sold into the EU. A 24-hour reporting window for actively exploited flaws is aggressive, and ActiveState's central point — as reported — is that meeting it depends on organizations already knowing exactly what shipped in their software and precisely when a given vulnerability was discovered. Vendors without accurate, up-to-date software composition and discovery records may struggle to meet the deadline even when they want to comply.
What to Watch and Do Now
- Inventory readiness: confirm you can produce an accurate, current software bill of materials (SBOM) for shipped products, including third-party and open-source components.
- Discovery timestamping: ensure internal vulnerability management and incident response processes reliably capture the exact moment a flaw is first identified as actively exploited, since that timestamp starts the reporting clock.
- Process ownership: identify who within your organization is responsible for CRA reporting decisions and ensure they have visibility into both vulnerability intake and exploitation-status intelligence.
- Cross-reference active exploitation signals (e.g., CISA KEV, vendor advisories, threat intel feeds) against your own product inventory so exploited-flaw determinations aren't delayed by manual lookups.
This is developing, net-new regulatory intel rather than a technical detection matter, and details on enforcement and practical vendor experience will likely evolve as the deadline passes. For the full analysis, see the original report from BleepingComputer.