Cyber Resilience Act: New reporting requirements for software manufacturers will take effect in September

Klicke hier für den deutschen Artikel.

Introduction

Starting on September 11, 2026, new legal reporting requirements will apply to many software manufacturers. On that date, the first practically relevant part of the Cyber Resilience Act (CRA) will take effect: Manufacturers of software and other products with digital elements must then report actively exploited vulnerabilities and serious security incidents — within specified timeframes (early warning within 24 hours, report within 72 hours, followed by a final report).

Important: This reporting requirement applies not only to new products but also to existing software already on the market. Even though the full product requirements of the CRA will not become mandatory until the end of 2027, software manufacturers should already have their processes in place to comply. This includes, in particular, a functioning vulnerability management system, clear responsibilities, and the ability to assess security incidents in a timely manner.

What does this mean for you?

If you develop or distribute software, you should check whether and to what extent the CRA applies to your products. In addition to the actual product requirements, the organizational aspects also play an important role:

  • How are security vulnerabilities reported and assessed?
  • Which components in use are affected?
  • Who decides on necessary measures?
  • How do security updates reach your users as quickly as possible?

Many companies are currently grappling with these questions — if you haven’t done so yet, now is a good time to start.

Security at combit

We, too, have aligned our processes with the CRA’s requirements. There are two distinct reporting channels:

Reports from you to us: If you discover a security vulnerability in one of our products, you can report it confidentially to our Computer Emergency Response Team (CERT) at cert@combit.net.

Reports from us to the authorities: Starting in September 2026, we will report actively exploited vulnerabilities and serious security incidents to the relevant authorities via the ENISA Single Reporting Platform in accordance with the CRA’s legal requirements.

We’ll keep you informed about known security vulnerabilities, as well as available measures and updates, via the private security section of our forum.

To ensure you receive security-related updates in a timely manner, we also recommend that you keep your subscription up to date. This will allow you to install necessary security updates without delay.

Conclusion

The Cyber Resilience Act makes it clear: product security is not a one-time task, but an ongoing process — for us as a manufacturer as well as for you as software developers and users.