Skip to content
Back to mrpetzai.de Tuesday, September 22, 2026 Edition 7 · 7 stories
Mr. Petz AI MrPetzAI AI News The weekly briefing for AI decision-makers
DE Germany

Product safety becomes a reporting duty as makers of digital products must now actively report incidents.

The Cyber Resilience Act now requires makers of digital products to report vulnerabilities starting September 11.

Regulation Executive
AI-GENERATED
Text size

Since September 11, 2026, makers of products with digital elements must report actively exploited vulnerabilities and severe security incidents through the EU platform CRA-SRP. Germany's federal cyber agency BSI acts as the national contact point and offers guidance for compliance.

Since September 11, 2026, reporting duties under the Cyber Resilience Act apply to makers of products with digital elements sold in the EU single market. They must report actively exploited vulnerabilities and severe security incidents as soon as they become aware of them. Reports are filed uniformly across the EU through the Single Reporting Platform, built by the EU cybersecurity agency ENISA. Recipients are the responsible national computer security incident response team and ENISA itself. In Germany, the federal computer emergency team inside BSI fills this role. No prior registration is required, and a report can reportedly be filed within minutes.

The duty marks a shift in European product safety policy. For the first time, makers of hardware and software with digital components must actively report incidents, not only operators of critical infrastructure as under the earlier NIS2 directive. Companies should check whether internal processes for detecting, assessing and reporting vulnerabilities on time already exist. Firms relying on suppliers outside the EU must also determine which national team is responsible in their case. For makers without a main base in the EU, responsibility depends on the location of their authorized representative, importer or distributor.

It remains unclear how strictly BSI and other national bodies will enforce the new deadlines in practice and where exactly the threshold for a severe incident lies. Smaller makers may feel the added administrative burden, even though the platform itself is described as simple to use. How reporting practice develops over coming months, and whether fines follow early cases, remains to be seen.

What this means for decision-makers

  • Check whether your products fall under the definition of digital elements covered by the Cyber Resilience Act.
  • Set up internal reporting channels so vulnerabilities can be filed through the CRA-SRP on time.
  • Clarify which national response team is responsible for your company, especially if based outside the EU.

This story was produced automatically from the source named above and checked by software before publication. The image is symbolic and shows neither the event nor a real person. How this paper is made

Free subscription

Get the whole edition by email. Free of charge.

Every Tuesday morning, seven documented stories with what each one means for your decisions. One click to unsubscribe.

Subscribe free of charge

No costs, no advertising, no forwarding of addresses.

Free subscription

The whole edition free of charge by email.

Seven documented stories from research, public authorities and standardisation – and what they mean for executives, marketing, HR and sales. No costs, one click to unsubscribe.

Subscribe free

Double opt-in: nothing is sent before you confirm the link in the email.

Editorial principles

Always the original source

Every story names its source and links to it directly. We do not pass on information we cannot trace.

Interpretation, not excitement

Every story states what it means for decisions in your company – concretely, not as a buzzword.

Organised by country

The United States sets the pace, Germany sets the frame. The other markets follow by actual AI activity.