Regulatory Watch  /  European Union  /  Final regulation
Moderate impactFinal regulationIn effect

EU Cyber Resilience Act reporting obligations take effect for manufacturers

As of September 11, 2026, manufacturers of products with digital elements are subject to new incident reporting obligations under the EU Cyber Resilience Act. The obligations require manufacturers to report cybersecurity incidents related to their products.

Why it matters: The EU Cyber Resilience Act now imposes mandatory incident reporting duties on manufacturers, raising compliance requirements for product security.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
EU Cyber Resilience Act Reporting Obligations Take Effect for Manufacturers
Hunton Privacy & Cybersecurity Law Blog · primary source · Sep 11, 2026
Details
JurisdictionEuropean Union
RegulatorEuropean Commission
LawCyber Resilience Act
StatusIn effect
PublishedSeptember 11, 2026
EffectiveSeptember 11, 2026
Organisationsmanufacturers of products with digital elements
Topicscybersecurity, breach notification, security