READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

EU's New 24-Hour Cyber Vulnerability Reporting Law Takes Effect Sept 11, But the Filing Platform Still Isn't Public

EU's New 24-Hour Cyber Vulnerability Reporting Law Takes Effect Sept 11, But the Filing Platform Still Isn't Public
The EU Cyber Resilience Act's mandatory 24-hour vulnerability reporting rule kicks in September 11, 2026, and as of today the government filing platform still has no published web address. Manufacturers also just learned the rule applies retroactively to products shipped years before the law existed, with zero time to test the system before the clock starts.

Ten days from now, on September 11, 2026, any company that sells a connected product in the European Union will be legally required to report an actively exploited cybersecurity vulnerability within 24 hours of finding out about it. As of today, the government platform they're supposed to use to do that has no public web address.

According to europeancompliancesuite, as of August 31, 2026, the Single Reporting Platform (SRP) "is not yet live" and its public access URL "has not yet appeared," even though ENISA has committed to having it operational the same day the legal obligation begins. Freshfields, the law firm, confirms the platform "is not yet live and is expected to become operational on 11 September 2026" — meaning the launch date and the deadline are the same date.

What the Law Actually Requires

The Cyber Resilience Act, formally Regulation (EU) 2024/2847, entered into force on December 10, 2024. Most of its requirements, things like secure-by-design engineering standards and formal software bills of materials, don't apply until December 11, 2027, according to erp.today. Article 14, the reporting chapter, runs on a separate and much faster clock.

Starting September 11, 2026, any manufacturer that becomes aware its product has an actively exploited vulnerability, or has suffered a "severe incident," must file an early warning within 24 hours, a fuller notification within 72 hours, and a final report within 14 days (for vulnerabilities) or one month (for incidents), according to Freshfields and Global Law Experts. Every report goes through the SRP and is routed to the relevant national Computer Security Incident Response Team (CSIRT) and to ENISA. Global Law Experts notes non-compliance can trigger administrative fines up to the maximum levels set by the regulation, though the firm does not specify a euro figure.

The Retroactive Catch Almost Nobody Planned For

Tech Times flags a detail that appears to have caught manufacturers off guard: many assumed the reporting duty only covers products launched after September 11. It doesn't. Article 69(3) of the regulation extends the obligation to every in-scope product already on the EU market, according to Tech Times, meaning a router shipped in 2022 or firmware installed during the pandemic is covered the moment a manufacturer learns it's being actively exploited. There is no grandfather clause for the reporting duty, even though the law didn't exist when those products shipped.

A Registration Process Missing a Piece

Compounding the platform delay, europeancompliancesuite reports the list of national CSIRTs designated as coordinators, the very authorities manufacturers must select from a dropdown menu during registration, "is still outstanding" as of publication. cyberresilienceact.eu, writing on August 24, 2026, likewise noted the CSIRT list wasn't yet published and advised manufacturers to at least create EU Login accounts in advance, since that step doesn't depend on the missing list or a live SRP.

Two Ways to Read the Timing

Global Law Experts and Tech Times both frame the compressed window as a straightforward operational risk: companies have no environment to test filings in before they're legally obligated to file for real.

The Hacker News offers a different read worth taking seriously. Its analysis argues the fifteen-month gap between the reporting duty (September 2026) and the actual engineering requirements (December 2027) isn't a drafting oversight, but a deliberate sequencing choice. "Mandating disclosure costs a regulator almost nothing," and forcing companies to report before they're required to fix anything gives Brussels a real-time inventory of how bad the vulnerability landscape actually is ahead of enforcing anything substantive. Under that reading, a reporting-only phase-in is a reasonable, low-burden way to gather data before imposing costlier design mandates rather than bureaucratic mismanagement.

Both things can be true. A regulator can have a defensible sequencing logic and still launch its mandatory filing system on the same day the legal deadline hits, giving zero window for dry runs. ENISA has published FAQs, registration guidance, and a classification framework tied to Commission Implementing Regulation (EU) 2025/2392, according to cyberresilienceact.eu, but guidance documents are not the same as a working, tested portal.

Separately, ETSI has submitted 17 draft cybersecurity standards for public review that would eventually let manufacturers demonstrate compliance with the CRA's later, 2027 engineering requirements, according to erp.today. That process runs into 2026 and has no bearing on the September 11 reporting deadline.

The open question heading into September 11: whether ENISA publishes the SRP's public URL and the full CSIRT coordinator list before manufacturers actually have something to report, or whether the first real-world test of the system happens during an active vulnerability disclosure with the 24-hour clock already running.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

unknown
Tech TimesEU Cyber Resilience Act Reporting Deadline: Filing Portal Launches Same Day It Becomes Mandatory - Tech Times
unknown
freshfieldsCyber Resilience Act reporting obligations take effect on 11 September 2026
unknown
europeancompliancesuiteCRA SRP: A Single Reporting Platform for Cyber Resilience Act Compliance
unknown
globallawexpertsEU Cyber Resilience Acts 24Hour Reporting Requirements
unknown
cyberresilienceact.euEighteen Days to CRA Reporting: What You Can Prepare Before the Platform Opens on 11 September 2026
unknown
The Hacker NewsThe EU CRA Will Make You Report What It Hasn't Yet Made You Fix
unknown
erp.todayEU Cyber Resilience Act: ETSI Advances 17 Standards as Reporting Deadline Nears