From baby monitors to smartwatches – EU's new 24-hour breach reporting rule targets consumer manufacturers
The new EU cybersecurity regulations will cover everything from smart home devices and apps to operating systems and VPNs.

Image by Cybernews.
- Manufacturers must warn ENISA, the EU cybersecurity agency, within 24 hours about exploited flaws and severe incidents.
- The rules cover products already on the EU market, from baby monitors and smartwatches to apps, routers, and operating systems.
- Manufacturers face additional 72-hour and final reporting deadlines under the Cyber Resilience Act.
- The CRA's full requirements are set to apply in December 2027.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The EU Commission announced new breach reporting rules on Friday requiring manufacturers of connected consumer devices and products to report “actively exploited vulnerabilities and severe security incidents” within 24 hours.
A new rule in the EU’s Cyber Resilience Act (CRA) – officially taking effect on September 11th – imposes a 24-hour deadline for manufacturers to “submit an early warning” breach notification to ENISA, the EU’s cybersecurity watchdog.
Manufacturers would then be required to follow up with “a full notification within 72 hours.” Furthermore, a final report must be submitted “no later than 14 days” after a manufacturer releases a patch to plug the active exploit.
In the case of a “severe” security event, the company will have one month after filing the 72-hour notification to submit its final report, the Commission said.
Rather than treating compliance as a series of isolated obligations, organizations should view these requirements as part of a broader cyber resilience strategy,said Louise Horton, Government Affairs Lead at NCC Group
“For many organizations, these reporting requirements will be the first real test of operational readiness," says Louise Horton, government affairs lead at NCC Group.
“Success will depend on having mature vulnerability management processes, visibility across products and dependencies, and the ability to identify, assess and report security issues quickly and accurately,” Horton further explained.
What products fall under the EU's new cyber rules?
According to Friday’s announcement, the CRA reporting obligations apply to “all products with digital elements made available in the EU, including those already on the market.”
In practice, this means consumers can rely on faster notifications and stronger protection for their connected devices, such as door locking systems, keeping their home safe and secure in the event of a cyberattack,”the EU Commission said.
Hardware and software categories will cover a slew of products, from everyday devices to the consumer-facing applications that power them.
Examples of covered products include baby monitors, smartwatches, connected home cameras, smart fridges, TVs, toys, smartphones, apps, computer games, routers, modems, operating systems, password managers, VPNs, smart speakers, smart thermostats, and more.
The new rules also apply to crypto wallet makers, while reporting requirements for open-source software stewards are set to take effect on December 11th, 2027.
Horton says the most prepared manufacturers will have already embedded secure-by-design principles into their product development lifecycle, as well as robust and established governance across software and supply chains.
“With the full requirements of the Cyber Resilience Act due to apply from December 2027, the message is clear: the implementation phase is now well underway, and organizations can no longer afford to defer preparation,” Horton said.
UK pushes ahead with its own 24-hour breach rule
Meanwhile, the UK government proposed its own breach notification rules last fall, with the same 24-hour and 72-hour reporting requirements to the UK National Cyber Security Centre (NCSC), and further covering regulated entities and data centers.
Currently, the UK Cyber Security and Resilience Bill is working its way through Parliament and is expected to pass by the end of 2026, with the new rules taking effect as soon as the bill receives Royal Assent.
The EU Cyber Resilience Act was passed in late 2024 to address what the agency called an inadequate level of cybersecurity in consumer products, as well as a lack of timely security updates.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.