Since September 11, 2026, manufacturers of products with digital elements on the EU market must report certain actively exploited vulnerabilities and severe incidents. Other main Cyber Resilience Act obligations apply later. Source officielle.
A practical check
Identify the manufacturer, product, vulnerability channel, and person responsible for reporting. Document the incident timeline and consult the official reporting platform.
A connected device sold online may be affected by a flaw reported to its maker. The retailer should know whom to contact and how to inform customers, while the manufacturer assesses and reports covered incidents.
What the evidence supports
The 24-hour and 72-hour deadlines apply to covered cases. A simple retailer should not assume it is the manufacturer without assessing its role. Date the check and retain the source documentation so that later changes can be verified.