The new obligation will be relevant not only to software developers or technology companies but also to companies placing smart devices, apps, internet-connected household or industrial equipment, and other products with digital elements on the EU market under their own name. They will have 24 hours from the moment they learn about a reportable vulnerability or incident to provide an early warning. Within 72 hours, they must provide more detailed information and an initial assessment.
Read more Art theft: Kaunas police investigate who stole a graphic work from the exhibition
This does not mean that the company must fix the vulnerability or resolve the incident within the first day. However, it must promptly assess whether the issue meets the reporting criteria set out in the Cyber Resilience Act. The deadline is counted from the moment the problem is discovered, not from the completion of an internal investigation, preparation of a fix, or management decision.

From September 11, the reporting obligations set out in Article 14 of the regulation will begin to apply, although most other requirements will apply from December 11, 2027. A practical approach to how businesses should assess the scope of the regulation and organize reporting is also provided by the non-binding European Commission guidelines published on July 27.
The obligation will affect not only technology companies
To understand which companies will have the new obligation, it is important to assess not their sector of activity but who is considered the product manufacturer under the Cyber Resilience Act. This is the person who designs or manufactures products with digital elements or organizes their design or manufacture and places them on the market under their own name or trademark. This includes not only products sold but also those monetized in other ways or, in certain cases, distributed for free in commercial activities.
Therefore, the manufacturer may not only be a programming company or electronics factory. The regulatory scope may also include companies in trade, industry, energy, or consumer goods that distribute a smart device, app, or other product with digital elements under their own name. These can be apps, routers, cameras, smartwatches, toys, household appliances, or internet-connected industrial equipment.
The most important factor is who places the product on the EU market under their own name or trademark. Simply using a purchased app or other digital product does not make a company its manufacturer. However, the reporting regime may also cover products previously placed on the market if the manufacturer learns about an actively exploited vulnerability or serious incident after the new obligations begin to apply.
Not every security flaw must be reported
Not every software bug, system malfunction, or vulnerability must be reported. The Cyber Resilience Act provides two specific grounds.
The first is an actively exploited vulnerability. There must be reliable data that a malicious actor has already exploited it in the system without the owner’s permission. Therefore, a theoretical flaw, laboratory test, publicly disclosed vulnerability number, or technical demonstration of the flaw does not necessarily mean active exploitation.
The second ground is a serious incident affecting product security. It is considered reportable if it negatively affects or may affect the product’s ability to protect the availability, authenticity, integrity, or confidentiality of important data or functions. The obligation may also arise when the incident has created or may create conditions to run malicious code in the product or its user systems. Mechanical failure, function malfunction, or performance slowdown without a cybersecurity element is not a reportable incident by itself.
An early warning must be provided within 24 hours, more detailed information and an initial assessment within 72 hours. The final vulnerability report must be submitted no later than 14 days after the corrective or risk-mitigating measure is implemented, and the serious incident report within one month of the 72-hour notification.
Read more Gold underfoot: 5 best ways to use fallen leaves in the garden
Trying to “fix the problem quietly” first is risky
The decision on whether to report cannot be left solely to the IT specialist, but it would also be dangerous to wait for a board meeting or manager’s signature. The regulation does not specify a particular decision-maker, so the company must establish an internal model in advance.
Technical facts should be determined by the specialist responsible for the product or cybersecurity, legal criteria by a lawyer or compliance function, and the appointed manager should be able to immediately approve the report. If necessary, data protection and communication specialists are involved in the process. It is also necessary to appoint a deputy employee, establish a 24/7 response procedure, and record when and what information the company received.
Internal organizational confusion will not stop the 24-hour deadline. Therefore, problem resolution and reporting must proceed in parallel. The early warning can be submitted without having all the answers, and more detailed information later. The company will not have the right to silently withhold the incident or delay reporting.
Administrative fines for violating the obligations set out in Article 14 can reach up to 15 million euros or 2.5% of the company’s total worldwide annual turnover of the previous financial year, applying the higher limit. These are maximum, not automatically imposed fines. Micro and small companies have a narrow exception regarding fines for missing the 24-hour deadline, but the reporting obligation itself, the 72-hour stage, and the final report remain.
From a legal perspective, the most dangerous thing is not that the company will not know all the facts within the first day, but that it will not be able to show when it learned about the problem, who assessed it, and why it was decided not to report.
Preparation will depend on contracts, and users will also feel the changes
If the product is developed by an external programmer but placed on the market under the customer’s name, the direct reporting obligation usually falls on the customer as the manufacturer. Therefore, contracts with developers should provide for an information transfer and cooperation mechanism measured in hours, not days. Otherwise, the company may not meet the 24-hour obligation.
Users will also feel the changes, although they themselves will not need to report incidents to authorities. The manufacturer must inform affected product users and, if necessary, indicate corrective or risk-mitigating measures. This may mean urgent software updates, prompts to change settings or passwords, temporarily disabling a vulnerable function, or in more severe cases, replacing the product.
Upon receiving a security notification, users should not delay the update for weeks. The new system will be effective only if the manufacturer quickly warns and the user quickly installs the fix.
Read more Do you think that the liver recovers after quitting alcohol? Scientists have unexpected news