EU Cyber Resilience Act: the 24-hour reporting rule for software vendors Posted in Blog | 2962 views. From 11 Sept 2026 the EU CRA gives software vendors 24 hours to report exploited vulnerabilities to ENISA. What all vendors must do now. Read more