Reporting has a clock
Manufacturers of products with digital elements are now subject to the Cyber Resilience Act’s reporting obligations, which began on September 11. The European Commission says the duties cover actively exploited vulnerabilities and severe incidents affecting product security. An early warning is due within 24 hours of awareness, followed by a fuller notification within 72 hours.
Notifications go through ENISA’s Single Reporting Platform to the relevant national computer security incident response team, with information also shared with ENISA subject to the specified exceptions. This is a reporting process for manufacturers, rather than a new account that household device owners must create.
A first milestone, not the whole law

The timetable matters. The Commission lists December 11, 2027 as the date of full application of the Act. It also says the reporting obligations for open-source software stewards start on that later date. September’s change should therefore not be described as every security requirement becoming mandatory at once.
For readers following connected-home technology, the consequence is greater attention to what happens after a product ships. Finding a fault, communicating it and delivering a correction are separate jobs. A reporting deadline does not itself prove that a particular camera, hub or storage device has received a fix.
What owners can check
Keep the exact model and installed software version in your device records, and use the manufacturer’s advisories when assessing an update. The questions raised by our earlier reporting on firewall maintenance remain useful: who maintains the equipment, and which services can reach it?
For systems holding personal files, planning a separate backup remains part of recovery preparation. The new reporting milestone is useful context for support expectations; it is not a reason to replace working equipment or assume that one brand is automatically safer.
