
Article 71 of Regulation (EU) 2024/2847 expressly makes Article 14 applicable from 11 September 2026, and both the European Commission and ENISA confirm that manufacturer reporting and the Single Reporting Platform are now live; the early signal was incomplete because severe security incidents are reportable alongside actively exploited vulnerabilities and the rule is not limited to EU-headquartered manufacturers.
European Union forces gadget makers to report hacks
Tech companies selling digital products in Europe must now notify authorities within 24 hours of discovering an active cyberattack.
In a nutshell
The European Union now requires makers of connected devices and software to report active cyberattacks and severe security incidents within 24 hours of finding them. The mandate, which took effect on 11 September 2026 under the Cyber Resilience Act, applies to both European and foreign manufacturers selling products in the bloc, including older models already on sale. While broader rules governing device design and manufacturing security do not arrive until December 2027, companies must now route breach alerts to European authorities and inform affected users.
Highlights
- Tech companies must send an initial cyberattack alert within 24 hours of becoming aware of an active exploit.
- Manufacturers must submit a comprehensive security notice within 72 hours of discovering an incident.
- Final reports are due within 14 days after a security fix is ready, or within one month for severe incidents.
- The reporting rule applies to connected products sold in the European Union before 11 December 2027.
- Broader European Union design, testing, and certification requirements remain paused until 11 December 2027.
From the Editor’s Diary
Mandatory disclosure ends the era of private incident handling, forcing technology companies to treat digital breaches as urgent public safety problems rather than private corporate secrets.
Who's involved
European Commission
the executive arm of the European Union that drafted the law and publishes practical guidance
goal → make the reporting rules clear and workable before broader product rules start in 2027
ENISA
the European Union Agency for Cybersecurity, which runs the central incident intake system
goal → collect and share breach notifications securely through a single digital system
Manufacturers of products with digital elements
companies that make or brand connected hardware and software sold in Europe
goal → catch cyberattacks, file notices within 24 and 72 hours, and tell affected customers
CSIRTs designated as coordinators
national Computer Security Incident Response Teams picked by member states as first responders
goal → review incident alerts and decide when sharing details might cause extra security danger
National market surveillance authorities
European government regulators that inspect products and enforce trade laws
goal → investigate violations and penalize companies that ignore reporting duties
Open-source software stewards
non-profit groups and foundations that support shared free software
goal → prepare for separate, lighter reporting rules that begin on 11 December 2027
In short
Tech companies can no longer keep active cyberattacks to themselves. Under Article 14 of the European Union's Cyber Resilience Act, makers of connected gadgets and software sold in the EU must now report active digital attacks to government authorities. This matters because it pulls digital security into the open, making companies tell regulators and customers when products in daily use are actively being broken into.
This change makes widespread government scrutiny of commercial software flaws likely next.
Whether that scrutiny succeeds is uncertain, because it depends on whether companies report problems quickly and whether European authorities can manage thousands of sensitive security alerts without leaking them.
How it unfolded
European Union plans a digital security law
The plan began as a broad policy initiative rather than a response to an emergency. European Commission President Ursula von der Leyen used her annual address to propose a Cyber Resilience Act for connected devices.
European lawmakers draft cybersecurity rules
The Commission drafted a formal regulation requiring tech companies to maintain security throughout a product's lifespan. Negotiators from member states and the European Parliament resolved differences and reached an agreement in late 2023, passing the draft in early 2024.
European Union sets a phased calendar
Lawmakers gave final approval to the statute and scheduled its obligations in stages. Most manufacturing and testing rules were deferred until 11 December 2027, but lawmakers scheduled incident reporting for 11 September 2026 and applied it even to older products already on the market.
Regulators create safeguards for secret flaw data
As technical work began, officials recognized that circulating sensitive exploit data too quickly could give hackers an advantage. The Commission published implementation guidance and adopted secondary rules that permit emergency delays in sharing reports if broader circulation creates cyber dangers.
Regulators release compliance instructions
Regulators published guidance clarifying who must report and how companies should assess security incidents. Law firms alerted global manufacturers that the reporting clock was approaching, while cybersecurity agency ENISA confirmed that past attacks discovered before September did not require retroactive notices.
Mandatory hack reporting begins
The reporting mandate took effect automatically across the European Union. ENISA launched the first version of its Single Reporting Platform, and the Commission reiterated that companies must report active malicious intrusions and major security disruptions.
Global companies face European reporting rules
The new mandate is strictly limited to incident reporting, leaving broader device security tests for 2027. Foreign manufacturers selling products in the EU must also comply, routing alerts to European national teams based on their business ties, corporate representatives, or local customer numbers.
Where things stand
The reporting system is active and functioning across Europe. Companies that discover active digital intrusions or severe incidents in connected products must now notify cybersecurity authorities through the central portal, send a detailed assessment within 72 hours, and notify users. European authorities have not yet released filing numbers or launched formal enforcement actions.
Attention now turns to real-world performance: whether companies report borderline incidents promptly, whether the portal handles large volumes of confidential alerts securely, and how regulators identify companies that fail to disclose breaches. The next major milestone arrives on 11 December 2027, when general device design and certification rules take effect.