Old Products, New Obligations: EU Cyber Resilience Act Reporting Is Now Live

16 Sep 2026
Client Alert

For most companies preparing for the EU Cyber Resilience Act (CRA), December 11, 2027 has been the date circled on the calendar. That is when the CRA’s broad product cybersecurity requirements (including vulnerability handling, security testing, and security updates) generally start to apply. But one important part of the CRA has become effective much earlier. Since September 11, 2026, manufacturers have been required to report certain actively exploited vulnerabilities and severe security incidents affecting products with digital elements (PDEs). And the reach of that obligation may be broader than many companies expect.

Read the full blog post.

We are Morrison Foerster — a global firm of exceptional credentials. Our clients include some of the largest financial institutions, investment banks, and Fortune 100, technology, and life sciences companies. Our lawyers are committed to achieving innovative and business-minded results for our clients, while preserving the differences that make us stronger.

Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations. Prior results do not guarantee a similar outcome.