Full Report
Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform
Analysis Summary
# Main Topic
EU manufacturers of products with digital elements must now disclose actively exploited vulnerabilities and severe security incidents within strict timeframes via ENISA’s Single Reporting Platform (SRP), as mandated by the Cyber Resilience Act (CRA). The regulation imposes a 24‑hour early warning, a 72‑hour detailed report, and final reports within 14 days (vulnerabilities) or 30 days (incidents), with penalties up to €15 million or 2.5 % of turnover for non‑compliance.
## Key Points
- **Mandatory Reporting Windows**
- 24 h: initial warning of an actively exploited flaw.
- 72 h: detailed notification.
- 14 days: final report after corrective action (vulnerabilities).
- 30 days: final report after incident mitigation (severe incidents).
- **Scope**
- Applies to all manufacturers of products with digital elements sold in the EU, regardless of domicile.
- Includes consumer IoT, industrial control systems, software, and any digital‑enabled device.
- **Reporting Platform**
- ENISA’s Single Reporting Platform (SRP) is the sole submission channel.
- Reports go to the CSIRT designated for the manufacturer’s main establishment (EU) or the appropriate coordinator (non‑EU).
- **User Notification**
- Manufacturers must inform affected users of the flaw and available mitigations without undue delay.
- **Penalties**
- Fines up to €15 million or 2.5 % of annual turnover, whichever is higher.
- **Broader Impact**
- Drives secure development, supply‑chain traceability (SBOM), and security‑by‑design requirements to kick in on 11 Dec 2027.
## Threat Actors
| Actor | Attribution | Motivation |
|-------|-------------|------------|
| ENISA / EU CSIRT | Regulatory bodies | Enforce cyber resilience, protect public safety |
| Potential malicious actors | Not specifically named | Exploit vulnerabilities in EU‑market products |
## TTPs
| Technique | Description | MITRE ATT&CK ID |
|-----------|-------------|-----------------|
| Vulnerability exploitation | Attackers actively exploit known flaws before patches | T1203, T1190 |
| Rapid reporting | Manufacturers must report within 24 h | N/A (regulatory compliance) |
| Incident mitigation | Prompt deployment of patches or mitigations | T1037, T1047 |
| Supply‑chain visibility | Creation and maintenance of SBOMs | T1595, T1597 |
## Affected Systems
- **Consumer IoT devices** (smart home, wearables, appliances)
- **Industrial control systems** (manufacturing, energy, utilities)
- **Software applications** with digital components (operating systems, middleware)
- **Connected vehicles** and automotive ECUs
- **Embedded systems** across all sectors that incorporate digital elements
## Mitigations
- **Secure Development Lifecycle (SDL)**: Integrate security from design through deployment.
- **SBOM Management**: Generate and maintain a Software Bill of Materials for every product release.
- **Rapid Patch Management**: Deploy fixes within the 24/72‑hour reporting windows; provide user‑friendly update mechanisms.
- **Incident Response Coordination**: Establish clear communication channels with CSIRT and users; prepare templates for rapid notifications.
- **Compliance Audits**: Conduct internal and external audits to verify adherence to CRA deadlines and reporting requirements.
- **Legal & Regulatory Liaison**: Maintain a dedicated compliance officer or team to track regulatory changes and coordinate reporting.
## Conclusion
The CRA’s enforcement of a 24‑hour reporting clock elevates the urgency of vulnerability discovery and remediation for manufacturers in the EU. Failure to comply can trigger substantial fines and reputational damage. By embedding secure development practices, maintaining comprehensive SBOMs, and establishing robust incident‑response workflows, manufacturers can meet the CRA’s stringent timelines, mitigate exploitation risks, and contribute to a more resilient cyber ecosystem across the EU.