Cyber security
From 11 September, manufacturers must report any vulnerabilities they discover to the EU agency ENISA within 24 hours – including details of the measures taken to rectify them.

Under the EU’s Cyber Resilience Act (CRA), new reporting obligations for manufacturers of digitally connected products will come into force on 11 September 2026. From this date, manufacturers must report vulnerabilities discovered in products to the European Union Agency for Cybersecurity (ENISA) within 24 hours – including details of the affected products, the nature and severity of the vulnerability, and the measures taken to remedy it. ENISA will compile these reports and make them publicly available. Entries will remain visible indefinitely and may lead to reputational risks if a company is listed repeatedly.
The new requirements aim to strengthen cyber security throughout the entire supply chain and to establish standardised, traceable processes for managing vulnerabilities. Until now, manufacturers have been able to respond to detected vulnerabilities at their own discretion and without fixed deadlines. The CRA now creates a binding, transparent framework that also covers responsibility for purchased components and software.
The reporting obligation applies to all manufacturers who place digital products with networked components on the market – ranging from consumer goods such as vacuum cleaners, fridges or cycle computers with Bluetooth interfaces to industrial machinery and safety-critical sensor technology. Products containing purchased software or hardware components are also affected. The key factor is that the product falls within the scope of the CRA.
If a vulnerability is discovered, the following information must be submitted to ENISA within 24 hours:
The vulnerability must also be reported if where it lies in a component purchased from a third party and incorporated into the company’s own product.
If vulnerabilities are not reported within the specified timeframe or are not adequately addressed, organisations face substantial fines of up to 15 million euros or 2.5 percent of their global annual turnover. In addition, permanent public listing on the ENISA website can result in significant reputational damage.
There is little time left before the reporting obligation comes into force. Organisations that have not yet established the necessary processes should act immediately.
The requirements also apply to small and medium-sized enterprises and may lead to significant resource constraints for them.
Different assessment providers may currently prioritise different areas, as no final standard has yet been published. The harmonised standards announced by ENISA provide guidance.
TÜV NORD has decades of experience and expertise in the testing and certification of cybersecurity-related processes and products. Around 70 specialists – over 40 of whom are based in Germany – support manufacturers in assessing and further developing their vulnerability management processes.
Under the Cyber Resilience Act, vulnerability management will become a mandatory requirement for manufacturers of digital products and a key competitive factor. Those who take action now will not only ensure their own compliance, but also safeguard their reputation and market position, whilst mitigating financial risks.

Matthias Springer is Senior Vice President of Functional Safety & Security at TÜV NORD. Photo: Frauke Schumann/TÜV NORD AG
This is an article from #explore. #explore is a digital journey of discovery into a world that is changing at a rapid pace. Increasing connectivity, innovative technologies and the all-encompassing digitalisation are creating new possibilities and turning the familiar upside down. But this also harbours dangers and risks: #explore shows a safe way through the connected world.