The EU Cyber Resilience Act reporting requirements came into force on 11 September 2026. These provisions require manufacturers of products with digital elements that are made available on the EU market to report any “exploited vulnerabilities” and “severe incidents” affecting the products.
The scope of “products with digital elements” is quite wide and encompasses software including apps and games as well as hardware such as laptops and machinery, amongst many other things.
If reports are made, privacy teams need to be aware as personal data might be affected and so notifications to data protection authorities/individuals might be needed. It is worth checking in with your IT colleagues to clarify whether your organisation is caught and make sure notifications are shared if so.
For more information, click here.