ADVERTISEMENT

From baby monitors to smartwatches – EU's new 24-hour breach reporting rule targets consumer manufacturers

The new EU cybersecurity regulations will cover everything from smart home devices and apps to operating systems and VPNs.

GDPR, cybersecurity, EU

Image by Cybernews.

Stefanie Schappert
Stefanie Schappert Senior Journalist
September 14, 2026 Updated: 42 seconds ago 2 min read
Key takeaways:
Rather than treating compliance as a series of isolated obligations, organizations should view these requirements as part of a broader cyber resilience strategy,
said Louise Horton, Government Affairs Lead at NCC Group

What products fall under the EU's new cyber rules?

IT devices examples, smart bulbs, smartphone, smart EU plugs, smart camera
Connected consumer devices covered by the EU Cyber Resilience Act. Image by Jakub Zerdzicki | Shutterstock
In practice, this means consumers can rely on faster notifications and stronger protection for their connected devices, such as door locking systems, keeping their home safe and secure in the event of a cyberattack,”
the EU Commission said.
ADVERTISEMENT
EU Cyber Resilience Act, CRA logo
The EU Cyber Resilience Act introduces new cybersecurity requirements for connected products sold in Europe. Image by Vector Image Plus | Shutterstock

UK pushes ahead with its own 24-hour breach rule

cyber insurance
The UK is advancing its own 24-hour cyber incident reporting requirements. Image by Cybernews
Stefanie Schappert
Senior Journalist
ADVERTISEMENT