27/07/2026
๐
11 September 2026: the day the EU Cyber Resilience Act's reporting rules start to bite โ over a year before the bigger 2027 deadlines.
If you buy connected hardware in the EU, this matters. From that date, manufacturers must report actively exploited vulnerabilities fast:
โฑ๏ธ 24h --> first warning
โฑ๏ธ 72h --> full report
You're not directly bound by the rules โ manufacturers are. But how a vendor handles reporting today is a free, early signal of their overall CRA readiness. A missing process is a red flag.
Three questions worth asking your vendors now ๐
๐ https://shopiot.eu/blogs/iot-industry-insights/eu-cyber-resilience-act-2026-reporting-deadline
Understand what the EU Cyber Resilience Act September 2026 reporting deadline means for IoT hardware buyers, vendors, and procurement teams.