The CRA Now Requires Reporting Exploited Vulnerabilities. What That Changes for You
Since 11 September 2026, manufacturers must report any actively exploited vulnerability within 24 hours through ENISA's platform. What this obligation changes, and does not change, for the way you prioritize patches.






