Skip to content
You can now search across every topic, entity and event.What's new
European Tech Sovereignty
22SEP

Cyber Resilience Act starts its clock

2 min read
10:47UTC

A manufacturer selling into the EU must now warn a competent authority within 24 hours of learning that a vulnerability in its product is under active exploitation.

TechnologyDeveloping
Key takeaway

EU manufacturers now have 24 hours to report an actively exploited vulnerability, with penalties reaching €15 million.

The Cyber Resilience Act (CRA), the EU's security law for products sold with digital elements, reached its first live enforcement date on 11 September 2026. A manufacturer selling into the EU must now warn a competent authority within 24 hours of learning that a vulnerability in its product is under active exploitation. A full notification follows within 72 hours. A final report is due within 14 days of a fix, or within a month of a severe incident 1. Penalties reach €15m. Full application of the Act follows in December 2027.

That clock now sets what compliance costs the smallest publisher in a supply chain as much as the largest vendor in it. CRA duties on open-source maintainers remain unsettled, because they sell nothing while their code ships inside products that do, and the obligation attaches to the commercial product rather than to the upstream code. Linux Foundation Europe and the Open Source Security Foundation have been preparing maintainer communities for precisely this date 2.

The 11 September date arrived on the calendar the Act itself set. This topic recorded the AI Omnibus entering into force on 27 July, widening the AI Office's supervisory reach to general-purpose models embedded inside large platforms and search engines, while leaving the AI Act's own dates untouched . Brussels has spent this year settling who supervises what across its digital rulebook. The Cyber Resilience Act is the instrument that now puts a duty on the manufacturer directly, counted in hours rather than in reporting periods.

Deep Analysis

In plain English

The Cyber Resilience Act is an EU law covering anything sold with software or a chip in it, from routers to smart fridges. From 11 September, companies must tell EU authorities within 24 hours if a serious security flaw in their product is being actively exploited by hackers. Miss the deadline and the fine can reach €15 million. For most readers it means products sold in Europe should get faster, more visible fixes when a hacking flaw is found.

Deep Analysis
Root Causes

The 24-hour duty closes a specific legal gap exposed by the Log4Shell vulnerability in December 2021, when a flaw in a widely used open-source logging library sat inside thousands of commercial products for months.

No law required anyone to tell EU authorities quickly. The Cyber Resilience Act turns that gap into a binding deadline rather than a best practice.

First Reported In

Update #16 · Germany's AI champion merges into Cohere

European Commission· 22 Sept 2026
Read original
Different Perspectives
ESMC (TSMC-majority joint venture)
ESMC (TSMC-majority joint venture)
ESMC's president said construction remains on schedule after the Dresden fab's topping-out ceremony on 14 September, reported by Focus Taiwan with first process equipment still targeted for the second half of 2027. No first-party ESMC or TSMC statement independently confirms the claim, and the fab remains 70% TSMC-owned inside a project Europe cites as its semiconductor sovereignty case.
Civo
Civo
Civo sold out its Navigate London sovereignty conference on 22 September, drawing about 800 attendees including a sitting MP, a former defence procurement minister and sponsors led by Nokia. Companies House confirms chief executive Mark Boost as Civo's sole person with significant control, British and UK-resident, which answers the ownership question the conference itself is arguing matters.
United States Trade Representative
United States Trade Representative
USTR opened its 2027 National Trade Estimate comment window on 14 September, naming the EU among markets with restrictive technology requirements and inviting submissions on cross-border data rules. The window follows Trump's 24 July Section 301 order into EU digital rules by seven weeks, and unused comments are kept, in USTR's own wording, for future negotiations.
Cohere
Cohere
Cohere published the deal on 16 September without naming a regulator, running the merged company globally under its own brand from dual Toronto and Berlin headquarters. It pledges the combined company will deliver sovereign AI on STACKIT, the Schwarz Group's German platform, aimed at government buyers weighing that offer against Berlin's own anchor-customer signal.
Germany (Federal Government)
Germany (Federal Government)
Digital Minister Karsten Wildberger called the Cohere talks "a very strong signal" and signalled Berlin's readiness to become an anchor customer, now its main lever since equity sits with Cohere. The German side secured a co-headquarters and two Cohere C-suite seats, but the protective-rights terms it pressed for in July remain undisclosed.
Poland
Poland
Poland leads a self-announced AI Gigafactory consortium with a EUR 100 million phase-one commitment, matched by Czechia and joined by Hungary at EUR 25 million. EuroHPC has confirmed no consortium for the call closing 12 November, so the bloc exists only in national announcements so far.