While the bulk of the EU Cyber Resilience Act's (CRA's) requirements won't take effect until December 2027, the reporting duty takes effect earlier, on September 11, 2026. Under this duty, affected companies must notify authorities and, in some cases, users, of any actively exploited vulnerabilities or severe incidents affecting their products within 24 hours of becoming aware. Wilson Sonsini attorneys Cédric Burton and Laura Brodahl weighed in on the practical implications for companies in Lexology Pro's recent article "Organisations Must Prepare for Mandatory 24-Hour Reporting Under EU Cyber Resilience Act," offering steps companies can take now to prepare.
"The CRA will turn product-security issues often handled internally today into regulatory exposure," said Cédric. "The vulnerability reporting duty has no materiality threshold beyond evidence of exploitation. Companies should therefore expect significant reporting volumes, especially as AI is rapidly accelerating vulnerability discovery."
"One of the best things in-house teams can do now is run a CRA tabletop exercise,” shared Laura. "Simulate an actively exploited vulnerability, start the 24-hour clock, and test whether the right people are looped in, understand the facts, make the reporting decision, and submit the notification in time. That will quickly expose gaps in ownership, escalation, and decision-making."
Click here to read the full article on Lexology Pro (subscription is required).