Cybersecurity, Laws

EU Cybersecurity Law's Reporting Clock Starts Ticking — But the Portal Isn't Ready

Published on 09/09/2026 at 16:03 | Editorial boerse-global.de

ENISA's reporting portal opens Sept 2026 without API, forcing manual submissions. Firms face 24-hour breach alerts, fines up to €15M.

EU Cyber Resilience Act: ENISA Portal Lacks API for Automated Reporting
EU Cybersecurity Law's Reporting Clock Starts Ticking — But the Portal Isn't Ready Illustration mit AI erstellt.

Manufacturers selling connected products in Europe face a hard deadline on September 11, 2026, when mandatory vulnerability reporting under the EU Cyber Resilience Act (CRA) kicks in. Yet the agency tasked with receiving those reports will launch its platform without the technical hooks that companies need for automated submissions.

The European Union Agency for Cybersecurity (ENISA) will open its central reporting portal on the compliance date without an application programming interface (API). That means affected businesses must type their incident and vulnerability notifications directly into a web interface rather than pushing data from their own security systems. Internal automation for preparing the information remains possible, but a seamless machine-to-machine link to Brussels is off the table for now.

The reporting rhythm is unforgiving. Once a manufacturer learns of an actively exploited vulnerability, a preliminary warning must reach authorities within 24 hours. A more detailed notification follows within 72 hours. For vulnerabilities, a final report lands after 14 days; for full-blown security incidents, the regulation allows a month. These obligations extend beyond newly launched hardware — existing devices already in circulation fall under the rules, as do manufacturers headquartered outside the EU whose products reach European customers.

Industry Readiness Lags Behind the Legal Timeline

Many companies are scrambling to catch up with what the law actually demands. A survey of 200 German industrial firms conducted by ONEKEY found that 45 percent have only superficial familiarity with the CRA's contents. Roughly 62 percent flagged the reporting duty as a major hurdle, with 30 percent calling it a serious problem. Nearly two-thirds — 61.5 percent — admitted they are unaware of other deadlines embedded in the regulation.

Despite that knowledge gap, half of the companies surveyed have already assembled dedicated CRA teams to manage compliance. Still, 13 percent doubt they can bring their product lines into line with the new requirements before December 11, 2027, the date when the rules apply to all products already on the market.

Cost Estimates and Calls for Enforcement

The European Commission projects total compliance spending across industry at €29 billion, roughly 2 percent of sector revenue. Some manufacturers argue that money is well spent. Austrian smart-lock maker Nuki, for instance, welcomes the CRA as validation of its own "security-by-design" philosophy. The company is pressing for rigorous market surveillance to level the playing field — a stance that resonates given that around 44 percent of survey respondents voiced security concerns about smart door locks.

Full enforcement of the CRA begins December 11, 2026. From that point, violations can trigger fines up to €15 million or 2.5 percent of worldwide annual turnover, whichever is higher. The regulation also mandates a minimum five-year support period for products with digital elements, ensuring that security updates follow devices well beyond their purchase date.

Disclaimer...

en | boerse | 70076058 |