EU calendar sets Cyber Resilience Act vulnerability reporting to start September 11
A European Commission factsheet published August 3 confirmed that reporting duties for actively exploited vulnerabilities and severe incidents begin on September 11, with part of the Data Act following a day later.
The European Commission published a compliance calendar on August 3 covering EU legislation that enters into force or becomes applicable between August 1 and September 15, with the Cyber Resilience Act among the September milestones.
The factsheet, referenced FS/26/1716, recorded September 11 as the date of partial application for Regulation (EU) 2024/2847. It said cybersecurity requirements for products with digital elements start to apply ahead of full application in 2027, and that reporting obligations concerning actively exploited vulnerabilities and severe incidents begin on that date. Partial application of the Data Act, Regulation (EU) 2023/2854, follows on September 12. The calendar also recorded the Artificial Intelligence Act becoming applicable on August 2, and Commission Implementing Regulation (EU) 2026/1755, which sets out how the Commission investigates and enforces breaches of that act, entering into force on August 10.
The document made no reference to road vehicles or automotive cybersecurity, and the Commission issued it as general information rather than sector guidance.
The boundary is drawn in the act itself. Article 2 of the Cyber Resilience Act states that it does not apply to products with digital elements covered by Regulation (EU) 2019/2144, the vehicle type-approval regulation — the instrument that carries the cybersecurity management and software-update requirements aligned with UN R155 and UN R156. Type-approved vehicles, systems and components therefore sit outside the September reporting duties, which fall instead on the wider connected-product supply chain that vehicle software is built from and sold alongside.