{"id":10576,"date":"2026-07-28T11:01:10","date_gmt":"2026-07-28T09:01:10","guid":{"rendered":"https:\/\/www.b2c-engineering.com\/?p=10576"},"modified":"2026-07-28T15:07:11","modified_gmt":"2026-07-28T13:07:11","slug":"cyber-resilience-act-enisa-notification-2026","status":"publish","type":"post","link":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/","title":{"rendered":"Cyber Resilience Act: What Will Change Starting September 11 2026"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"10576\" class=\"elementor elementor-10576 elementor-10575\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-5684664 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"5684664\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-08c5fff\" data-id=\"08c5fff\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-be63021 elementor-widget elementor-widget-text-editor\" data-id=\"be63021\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The <strong>Cyber Resilience Act<\/strong> (CRA), Regulation (EU) 2024\/2847, entered into force on 10 December 2024. Most of its obligations will apply from <strong>11 December 2027<\/strong>.<\/p>\n<p><strong>A first deadline arrives well before that date. <\/strong><\/p>\n<p>From <strong>11 September 2026<\/strong>, manufacturers of PLCs, HMIs, industrial gateways and connected products more broadly will have to notify certain cybersecurity incidents to <a href=\"https:\/\/www.enisa.europa.eu\/\">ENISA<\/a> (the European Union Agency for Cybersecurity) and to the competent CSIRT (the national <em>Computer Security Incident Response Team<\/em> of the Member State concerned).<\/p>\n<p>This obligation falls on your equipment suppliers and on your industrial software publishers, not directly on you as an industrial operator. <br \/>But it does concern you: <strong>it determines how they will have to manage and communicate about vulnerabilities in the PLCs, HMIs, gateways and software (SCADA, MES, historian systems&#8230;) already installed on your sites.<\/strong><\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-8cdbee7 elementor-widget elementor-widget-image\" data-id=\"8cdbee7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<img fetchpriority=\"high\" decoding=\"async\" width=\"2560\" height=\"1442\" src=\"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg\" class=\"attachment-full size-full wp-image-9154\" alt=\"\" srcset=\"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg 2560w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-300x169.jpg 300w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-1024x577.jpg 1024w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-768x433.jpg 768w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-1536x865.jpg 1536w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-2048x1154.jpg 2048w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/>\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3cce435 elementor-widget elementor-widget-button\" data-id=\"3cce435\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/www.b2c-engineering.com\/en\/industrial-cybersecurity-nis2\/\" target=\"_blank\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Discover our cybersecurity solutions<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-7cf99bc elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"7cf99bc\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-6c6deff\" data-id=\"6c6deff\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-1aefbb0 elementor-widget elementor-widget-heading\" data-id=\"1aefbb0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What is the Cyber Resilience Act?<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bfd9c37 elementor-widget elementor-widget-text-editor\" data-id=\"bfd9c37\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The CRA sets cybersecurity requirements for any \u00ab <strong>product with digital elements<\/strong> \u00bb placed on the European market: hardware, software, and components such as chips or operating systems sold separately. It covers the product&#8217;s entire lifecycle, from design to maintenance during the support period set by the manufacturer.<\/p>\n<p><strong>Before placing a product on the market<\/strong>, the manufacturer assesses cybersecurity risks and documents its compliance with the regulation&#8217;s essential requirements.<\/p>\n<p><strong>After the product is placed on the market<\/strong>, the manufacturer remains responsible. It must manage vulnerabilities throughout the announced support period, and report those that are actively exploited as well as severe incidents. This last obligation is the first to become effective.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-3fcb883 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"3fcb883\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-e21da58\" data-id=\"e21da58\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-aeacfd8 elementor-widget elementor-widget-heading\" data-id=\"aeacfd8\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Cyber Resilience Act: the first notification deadline, from 11 September 2026<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-5a42384 elementor-widget elementor-widget-text-editor\" data-id=\"5a42384\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>From that date, your PLC, HMI and gateway suppliers, as well as your industrial software publishers, will have to report:<\/p>\n<ul>\n<li><strong>Any actively exploited vulnerability<\/strong> affecting a product with digital elements,<\/li>\n<li><strong>Any severe incident<\/strong> affecting the security of that product.<\/li>\n<\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9508f80 elementor-widget elementor-widget-heading\" data-id=\"9508f80\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">1. Who is concerned<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7c2bc66 elementor-widget elementor-widget-text-editor\" data-id=\"7c2bc66\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The obligation applies to the manufacturer of the product, not the company using it. In practice, it is your PLC, HMI or gateway supplier who will have to notify, not you.<\/p>\n<p>The regulation is not limited to hardware: industrial software (SCADA, MES, historian systems&#8230;) is also a \u00ab <strong>product with digital elements<\/strong> \u00bb. Its publisher is therefore subject to the same reporting obligations as a PLC or gateway manufacturer.<\/p>\n<p>It also applies to products already installed before <strong>11 December 2027<\/strong>. <br \/>The European Commission states this explicitly: <b>a PLC installed on one of your sites for several years falls within scope, just like a new product.<\/b><\/p>\n<p>If your company itself designs equipment that it sells, not only for its own use, it may also be <b>considered a manufacturer<\/b> under the regulation. <br \/>The exact category of the products is worth checking with a specialised legal advisor: the regulation provides for \u00ab important \u00bb and \u00ab critical \u00bb categories subject to stricter procedures (Annexes III and IV).<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4100bc1 elementor-widget elementor-widget-heading\" data-id=\"4100bc1\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">2. Deadlines your suppliers will have to respect<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-1ed71d7 elementor-widget__width-initial elementor-widget elementor-widget-text-editor\" data-id=\"1ed71d7\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The regulation sets a precise notification timeline:<\/p>\n<ul>\n<li>An early warning within <strong>24 hours<\/strong> of becoming aware of the incident or vulnerability,<\/li>\n<li>A full notification within <strong>72 hours<\/strong>,<\/li>\n<li>A final report, no later than <strong>14 days<\/strong> after a corrective measure becomes available, or within <strong>one month<\/strong> for a severe incident.<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<p>Micro and small enterprises cannot be penalised for failing to meet the <strong>24-hour<\/strong> deadline alone.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-aed3b6e elementor-widget elementor-widget-heading\" data-id=\"aed3b6e\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">3. How the notification is handled<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-93e1eab elementor-widget elementor-widget-text-editor\" data-id=\"93e1eab\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Notification goes through the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-reporting\">CRA Single Reporting Platform (SRP)<\/a>, set up by ENISA and operational from 11 September 2026. The supplier submits its notification to the CSIRT of its main Member State, as well as to ENISA.<\/p>\n<p>Each Member State designates its own national CSIRT. In Belgium, for example, this is the <a href=\"https:\/\/ccb.belgium.be\/regulation\/cra\">Centre for Cybersecurity Belgium (CCB)<\/a>, which already publishes its own resources on the CRA. Depending on the supplier&#8217;s country of establishment, an equivalent contact exists.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-f4fa561 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"f4fa561\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-b8658b0\" data-id=\"b8658b0\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-c8db2c6 elementor-widget elementor-widget-heading\" data-id=\"c8db2c6\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">What this means for you, as an industrial operator.<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-891a8e0 elementor-widget elementor-widget-text-editor\" data-id=\"891a8e0\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The CRA does not require you to notify anything yourself. But it changes what you can expect from your suppliers, and a few questions are worth asking now:<\/p>\n<ul>\n<li>Do your PLC, HMI and gateway suppliers, and your industrial software publishers, have a clear point of contact for reporting a vulnerability?<\/li>\n<li>Is your installed base mapped well enough to quickly identify which equipment would be affected if a supplier reports a vulnerability?<\/li>\n<li>Do your contracts specify the support period and security update commitments of your suppliers?<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<p>Answering these questions now, rather than on <b>11 September 2026<\/b>, makes it easier to handle these conversations with suppliers without improvisation on the day a vulnerability needs to be communicated.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-a9bf52c elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"a9bf52c\" data-element_type=\"section\" data-e-type=\"section\" data-settings=\"{&quot;background_background&quot;:&quot;classic&quot;}\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-06bcc90\" data-id=\"06bcc90\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a1202d9 elementor-widget elementor-widget-heading\" data-id=\"a1202d9\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Would you like to discuss your industrial cybersecurity challenges?\u200b\u200b<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<section class=\"elementor-section elementor-inner-section elementor-element elementor-element-d7d80e0 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d7d80e0\" data-element_type=\"section\" data-e-type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-e165f50\" data-id=\"e165f50\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t<div class=\"elementor-element elementor-element-f6c2f01 elementor-position-left elementor-vertical-align-middle elementor-widget__width-initial elementor-widget elementor-widget-image-box\" data-id=\"f6c2f01\" data-element_type=\"widget\" data-e-type=\"widget\" data-widget_type=\"image-box.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<div class=\"elementor-image-box-wrapper\"><figure class=\"elementor-image-box-img\"><a href=\"http:\/\/outlook.office.com\/bookwithme\/user\/257c00a5d7a342318d2754cd0a3a94d7%40b2c-engineering.com\/meetingtype\/rdbAwfzB506LizBKY2Su1A2?bookingcode=7e3a6d43-5034-4b61-8c93-3dca8b099811&#038;anonymous&#038;ismsaljsauthenabled\" target=\"_blank\" tabindex=\"-1\"><img decoding=\"async\" width=\"800\" height=\"800\" src=\"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2026\/02\/1670495911614.jpeg\" class=\"attachment-full size-full wp-image-9866\" alt=\"Johan, Business Development Engineer CSI de B2C Engineering\" srcset=\"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2026\/02\/1670495911614.jpeg 800w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2026\/02\/1670495911614-300x300.jpeg 300w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2026\/02\/1670495911614-150x150.jpeg 150w, https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2026\/02\/1670495911614-768x768.jpeg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/a><\/figure><div class=\"elementor-image-box-content\"><p class=\"elementor-image-box-description\"><b>Johan FOIREST<\/b>\n<br><b>Business Development Engineer Cybersecurity<\/b>\n<br>Email : jfoi@b2c-engineering.com<\/p><\/div><\/div>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-99c4f2f elementor-align-left elementor-widget__width-initial elementor-invisible elementor-widget elementor-widget-button\" data-id=\"99c4f2f\" data-element_type=\"widget\" data-e-type=\"widget\" data-settings=\"{&quot;_animation&quot;:&quot;fadeIn&quot;}\" data-widget_type=\"button.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div class=\"elementor-button-wrapper\">\n\t\t\t\t\t<a class=\"elementor-button elementor-button-link elementor-size-sm\" href=\"https:\/\/outlook.office.com\/bookwithme\/user\/257c00a5d7a342318d2754cd0a3a94d7@b2c-engineering.com\/meetingtype\/rdbAwfzB506LizBKY2Su1A2?bookingcode=d7a85333-caf2-4622-9441-d65146d4e65b&#038;anonymous&#038;ismsaljsauthenabled\">\n\t\t\t\t\t\t<span class=\"elementor-button-content-wrapper\">\n\t\t\t\t\t\t\t\t\t<span class=\"elementor-button-text\">Book a 30-minute session<\/span>\n\t\t\t\t\t<\/span>\n\t\t\t\t\t<\/a>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t<div class=\"elementor-column elementor-col-50 elementor-inner-column elementor-element elementor-element-38a7232\" data-id=\"38a7232\" data-element_type=\"column\" data-e-type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap\">\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Cyber Resilience Act: Starting September 11, 2026, manufacturers of connected products must report vulnerabilities to ENISA.<\/p>\n","protected":false},"author":7,"featured_media":9154,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[17],"tags":[],"class_list":["post-10576","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber Resilience Act: What Will Change Starting September 11 2026<\/title>\n<meta name=\"description\" content=\"Cyber Resilience Act: as of September 11, 2026, connected product manufacturers must report exploited vulnerabilities to ENISA.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber Resilience Act: What Will Change Starting September 11 2026\" \/>\n<meta property=\"og:description\" content=\"Cyber Resilience Act: as of September 11, 2026, connected product manufacturers must report exploited vulnerabilities to ENISA.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"B2C Engineering\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-28T09:01:10+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-28T13:07:11+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1442\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Emilie Fenoul\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Emilie Fenoul\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/\"},\"author\":{\"name\":\"Emilie Fenoul\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#\\\/schema\\\/person\\\/b7fdc3b92adbfc40d0fadd9b675c2427\"},\"headline\":\"Cyber Resilience Act: What Will Change Starting September 11 2026\",\"datePublished\":\"2026-07-28T09:01:10+00:00\",\"dateModified\":\"2026-07-28T13:07:11+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/\"},\"wordCount\":758,\"publisher\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.b2c-engineering.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/7_20251002-DSCF3475-scaled.jpg\",\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/\",\"url\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/\",\"name\":\"Cyber Resilience Act: What Will Change Starting September 11 2026\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.b2c-engineering.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/7_20251002-DSCF3475-scaled.jpg\",\"datePublished\":\"2026-07-28T09:01:10+00:00\",\"dateModified\":\"2026-07-28T13:07:11+00:00\",\"description\":\"Cyber Resilience Act: as of September 11, 2026, connected product manufacturers must report exploited vulnerabilities to ENISA.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.b2c-engineering.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/7_20251002-DSCF3475-scaled.jpg\",\"contentUrl\":\"https:\\\/\\\/www.b2c-engineering.com\\\/wp-content\\\/uploads\\\/2025\\\/10\\\/7_20251002-DSCF3475-scaled.jpg\",\"width\":2560,\"height\":1442},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/cyber-resilience-act-enisa-notification-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cyber Resilience Act: What Will Change Starting September 11 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/\",\"name\":\"B2C Engineering\",\"description\":\"Creating Smart Factories Together\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#organization\",\"name\":\"B2C Engineering\",\"url\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.b2c-engineering.com\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/logo-B2C-engineering.svg\",\"contentUrl\":\"https:\\\/\\\/www.b2c-engineering.com\\\/wp-content\\\/uploads\\\/2022\\\/03\\\/logo-B2C-engineering.svg\",\"caption\":\"B2C Engineering\"},\"image\":{\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/#\\\/schema\\\/person\\\/b7fdc3b92adbfc40d0fadd9b675c2427\",\"name\":\"Emilie Fenoul\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a9fb45623987a6008a7c540ffb7d7f7b628be739dd04faf0658e3185f7511b58?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a9fb45623987a6008a7c540ffb7d7f7b628be739dd04faf0658e3185f7511b58?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a9fb45623987a6008a7c540ffb7d7f7b628be739dd04faf0658e3185f7511b58?s=96&d=mm&r=g\",\"caption\":\"Emilie Fenoul\"},\"url\":\"https:\\\/\\\/www.b2c-engineering.com\\\/en\\\/author\\\/emilie\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber Resilience Act: What Will Change Starting September 11 2026","description":"Cyber Resilience Act: as of September 11, 2026, connected product manufacturers must report exploited vulnerabilities to ENISA.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/","og_locale":"en_US","og_type":"article","og_title":"Cyber Resilience Act: What Will Change Starting September 11 2026","og_description":"Cyber Resilience Act: as of September 11, 2026, connected product manufacturers must report exploited vulnerabilities to ENISA.","og_url":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/","og_site_name":"B2C Engineering","article_published_time":"2026-07-28T09:01:10+00:00","article_modified_time":"2026-07-28T13:07:11+00:00","og_image":[{"width":2560,"height":1442,"url":"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg","type":"image\/jpeg"}],"author":"Emilie Fenoul","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Emilie Fenoul","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/#article","isPartOf":{"@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/"},"author":{"name":"Emilie Fenoul","@id":"https:\/\/www.b2c-engineering.com\/en\/#\/schema\/person\/b7fdc3b92adbfc40d0fadd9b675c2427"},"headline":"Cyber Resilience Act: What Will Change Starting September 11 2026","datePublished":"2026-07-28T09:01:10+00:00","dateModified":"2026-07-28T13:07:11+00:00","mainEntityOfPage":{"@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/"},"wordCount":758,"publisher":{"@id":"https:\/\/www.b2c-engineering.com\/en\/#organization"},"image":{"@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg","inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/","url":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/","name":"Cyber Resilience Act: What Will Change Starting September 11 2026","isPartOf":{"@id":"https:\/\/www.b2c-engineering.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/#primaryimage"},"image":{"@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg","datePublished":"2026-07-28T09:01:10+00:00","dateModified":"2026-07-28T13:07:11+00:00","description":"Cyber Resilience Act: as of September 11, 2026, connected product manufacturers must report exploited vulnerabilities to ENISA.","breadcrumb":{"@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/#primaryimage","url":"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg","contentUrl":"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2025\/10\/7_20251002-DSCF3475-scaled.jpg","width":2560,"height":1442},{"@type":"BreadcrumbList","@id":"https:\/\/www.b2c-engineering.com\/en\/cyber-resilience-act-enisa-notification-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.b2c-engineering.com\/en\/"},{"@type":"ListItem","position":2,"name":"Cyber Resilience Act: What Will Change Starting September 11 2026"}]},{"@type":"WebSite","@id":"https:\/\/www.b2c-engineering.com\/en\/#website","url":"https:\/\/www.b2c-engineering.com\/en\/","name":"B2C Engineering","description":"Creating Smart Factories Together","publisher":{"@id":"https:\/\/www.b2c-engineering.com\/en\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.b2c-engineering.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.b2c-engineering.com\/en\/#organization","name":"B2C Engineering","url":"https:\/\/www.b2c-engineering.com\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.b2c-engineering.com\/en\/#\/schema\/logo\/image\/","url":"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2022\/03\/logo-B2C-engineering.svg","contentUrl":"https:\/\/www.b2c-engineering.com\/wp-content\/uploads\/2022\/03\/logo-B2C-engineering.svg","caption":"B2C Engineering"},"image":{"@id":"https:\/\/www.b2c-engineering.com\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.b2c-engineering.com\/en\/#\/schema\/person\/b7fdc3b92adbfc40d0fadd9b675c2427","name":"Emilie Fenoul","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a9fb45623987a6008a7c540ffb7d7f7b628be739dd04faf0658e3185f7511b58?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a9fb45623987a6008a7c540ffb7d7f7b628be739dd04faf0658e3185f7511b58?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a9fb45623987a6008a7c540ffb7d7f7b628be739dd04faf0658e3185f7511b58?s=96&d=mm&r=g","caption":"Emilie Fenoul"},"url":"https:\/\/www.b2c-engineering.com\/en\/author\/emilie\/"}]}},"_links":{"self":[{"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/posts\/10576","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/comments?post=10576"}],"version-history":[{"count":5,"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/posts\/10576\/revisions"}],"predecessor-version":[{"id":10623,"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/posts\/10576\/revisions\/10623"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/media\/9154"}],"wp:attachment":[{"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/media?parent=10576"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/categories?post=10576"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.b2c-engineering.com\/en\/wp-json\/wp\/v2\/tags?post=10576"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}