Cybersecurity

Hiding a hack just became illegal in Europe — device makers have 24 hours to report

Susan Hill

Selling a connected device in Europe now comes with an obligation that did not exist last week: discover a hack or a severe security incident, and authorities must be notified within 24 hours. The EU’s Cyber Resilience Act crossed its first major enforcement threshold this week, and the chain is specific — a fuller notification follows within 72 hours, with a final report due 14 days after a fix becomes available, or within one month for broader incidents.

The obligation covers what the law calls ‘products with digital elements’ — a category broad enough to include smartphones, smart thermostats, connected routers, fitness apps, and cloud platforms. Critically, it applies to products already on the EU market, not only new releases. A device shipped two years ago and still in use is within scope if it carries connected functionality. Free software distributed commercially falls under the same rules.

Before September 11, the relationship between a manufacturer and a security incident was largely governed by internal policy. Companies disclosed hacks when they chose to, often after weeks of internal review, legal consultation, and brand risk assessment. Some never disclosed at all. That discretion is now gone in Europe. Reports go to the national Computer Security Incident Response Team of whichever EU member state holds the manufacturer’s main establishment, with copies to the EU Agency for Cybersecurity, ENISA, via a dedicated Single Reporting Platform.

The readiness question is serious. When the reporting obligations were finalized, manufacturers had approximately three months to build the internal infrastructure — an inventory of affected products, clear escalation protocols, and technical integration with the Single Reporting Platform. Legal advisers working with manufacturers warn that the windows leave almost no time to construct the process after an incident has started. A company that discovers a breach at midnight on a Friday must submit its initial report before midnight on Saturday, irrespective of the weekend or public holidays.

The consumer-facing benefit is real but indirect. Manufacturers must also notify affected users about security incidents and available mitigations. If a company fails to notify users in a timely way, national cybersecurity authorities can step in and issue the alert themselves. This is not a notification regime the average user will see on their phone — it operates through regulatory channels — but it creates an enforceable obligation that hacks cannot simply be absorbed quietly by a legal team.

September 11 is the narrowest part of the obligation. The fuller body of the Cyber Resilience Act — requiring connected products to be designed with security built in, mandating vulnerability-handling processes, and imposing conformity assessments for the highest-risk product categories — does not apply until December 11, 2027. That deadline requires design changes, testing protocols, and certification processes that simply cannot be bolted onto existing product lines in a few months. The industry has more than a year, but the technical work is already underway at major manufacturers.

The EU’s approach makes Europe the first major regulatory bloc to impose binding vulnerability disclosure timelines across the full consumer technology market, not just critical infrastructure. How swiftly national CSIRTs develop the capacity to process these reports — and whether enforcement follows disclosure failures in the first months — will determine whether September 11 marks a real shift or a paper deadline.

Tags: , , , , ,

Discussion

There are 0 comments.