EU Cyber Resilience Act: the 24-hour reporting rule for small software vendors Posted in Blog | 52 views. From 11 Sept 2026 the EU CRA gives software vendors 24 hours to report exploited vulnerabilities to ENISA. What small vendors must do now. Read more