The Cyber Resilience Act (CRA), the EU's security law for products sold with digital elements, reached its first live enforcement date on 11 September 2026. A manufacturer selling into the EU must now warn a competent authority within 24 hours of learning that a vulnerability in its product is under active exploitation. A full notification follows within 72 hours. A final report is due within 14 days of a fix, or within a month of a severe incident 1. Penalties reach €15m. Full application of the Act follows in December 2027.
That clock now sets what compliance costs the smallest publisher in a supply chain as much as the largest vendor in it. CRA duties on open-source maintainers remain unsettled, because they sell nothing while their code ships inside products that do, and the obligation attaches to the commercial product rather than to the upstream code. Linux Foundation Europe and the Open Source Security Foundation have been preparing maintainer communities for precisely this date 2.
The 11 September date arrived on the calendar the Act itself set. This topic recorded the AI Omnibus entering into force on 27 July, widening the AI Office's supervisory reach to general-purpose models embedded inside large platforms and search engines, while leaving the AI Act's own dates untouched . Brussels has spent this year settling who supervises what across its digital rulebook. The Cyber Resilience Act is the instrument that now puts a duty on the manufacturer directly, counted in hours rather than in reporting periods.
