What Happened
Starting September 11, the European Union’s Cyber Resilience Act imposes a strict new reporting duty on manufacturers selling connected products with digital elements into the EU market. Once a company becomes aware of an actively exploited vulnerability or a severe security incident affecting one of those products, it must file an early warning with the EU Agency for Cybersecurity, ENISA, within 24 hours, follow up with a full notification within 72 hours, and submit a final report within 14 days of a fix or one month of the incident. ENISA’s Single Reporting Platform and a network of national computer security incident response teams go live the same day to receive these filings. The duty covers legacy products already sold in the EU, not only new releases, and penalties for noncompliance reach 15 million euros or 2.5 percent of a company’s global annual revenue, whichever is higher. Full coverage is available from Dark Reading.
Why This Matters for Canadian Organizations
Any Canadian company manufacturing or selling hardware or software with digital elements into the EU, from industrial sensors to SaaS platforms serving EU customers, now falls under this reporting duty regardless of where the company sits. This includes Canadian firms without an EU subsidiary shipping product through distributors or online storefronts reaching European customers. The 24-hour clock runs considerably tighter than the incident-reporting timelines contemplated under Canada’s own Bill C-26, giving compliance and legal teams a preview of the pace regulators now expect for vulnerability disclosure. Organizations already reporting to the Canadian Centre for Cyber Security under voluntary or sector-specific arrangements need a parallel process for EU-bound products rather than relying on domestic timelines.
What to Do
Identify which products your organization sells or has sold into the EU market, including through resellers, and confirm whether any contain digital elements covered by the CRA. Build a 24-hour internal escalation path from product security or engineering to whoever will file with ENISA, since the clock starts the moment your organization becomes aware of exploitation, not when a fix ships. Legal and compliance teams should map this deadline against existing Bill C-26 and provincial privacy-breach duties to avoid conflicting internal timelines. Vendors uncertain about scope should consult EU counsel now rather than after their first reportable incident.






