Cyber Resilience Act: what changes with the obligation to report vulnerabilities

7 de October de 2026
Cyber Resilience Act

The Cyber Resilience Act is no longer a distant regulation. Since 11 September 2026, manufacturers of products with digital elements sold in the European Union must report actively exploited vulnerabilities and severe incidents within 24 hours.

It is the first obligation of the regulation that is already enforceable, and it arrives more than a year before full application. In this article we review what changes, who is affected (Spain, Mexico, Colombia, Peru and Chile), which deadlines apply and why the starting point is always the same: knowing exactly what technology you have and where it is.

What is the Cyber Resilience Act?

The Cyber Resilience Act (CRA) is Regulation (EU) 2024/2847. It sets common cybersecurity requirements for every product with digital elements placed on the EU market, whether software or connected hardware.

Its underlying idea is that security should be part of the product from design and throughout its lifecycle, rather than depending on after-the-fact patches. It applies in stages:

DateMilestone
10 December 2024Entry into force of the regulation
11 September 2026Obligation to report exploited vulnerabilities and severe incidents (Article 14)
11 December 2027Full application of the remaining requirements, including CE marking

What changes from 11 September 2026

Article 14 requires manufacturers to report two things: any vulnerability in their product that is being actively exploited, and any severe incident affecting its security.

The notification goes simultaneously to ENISA and to the coordinating CSIRT of the country where the manufacturer has its main establishment. In Spain, that CSIRT is INCIBE-CERT. There is a single channel: the Single Reporting Platform (SRP) managed by ENISA, operational from that same date.

Reporting deadlines

DeadlineWhat must be sent
24 hoursEarly warning from the moment of awareness
72 hoursNotification with the information available
14 daysFinal report on an exploited vulnerability
1 monthFinal report on a severe incident

In addition, the manufacturer must inform affected users and, where appropriate, indicate measures to mitigate the risk.

What the Cyber Resilience Act does not yet require (and who it affects)

The scope of this first phase is narrower than it seems. On 27 July 2026 the European Commission published a first interpretative guidance clarifying several points:

  • It is not retroactive. Anything the manufacturer already knew before 11 September 2026 does not have to be reported.
  • Only real exploitation counts. The mere existence of a vulnerability does not trigger the obligation; active exploitation does.
  • It still applies after end of support. The reporting obligation does not end when the product is no longer supported.

The obligation falls on the manufacturer. But the impact also reaches organisations that use those products: they will receive alerts from their vendors far more often and faster, and will only be able to react in time if they know which devices and which software are affected.

CRA, NIS2 and ENS: pieces of the same puzzle

The Cyber Resilience Act does not replace other regulations: it complements them. NIS2 and Spain's National Security Framework (ENS) focus on how organisations manage their risks, including supply-chain security. The CRA, by contrast, targets the security of the products that supply chain delivers.

In practice, all three frameworks ask IT teams for the same thing: a reliable inventory, documented vulnerability management and rapid response capability. Those already working this way to comply with NIS2 or the ENS are well on their way.

What about other countries? Why the CRA matters to you too

The Cyber Resilience Act applies to every product with digital elements sold in the EU, regardless of where the manufacturer is based. A company from Mexico, Colombia, Peru or Chile selling software or connected devices in Europe has the same reporting obligations from 11 September 2026.

And even if you do not sell in Europe, the CRA affects you as a user. Much of the software used by Latin American organisations comes from vendors operating in the European market, so their vulnerability alerts will arrive sooner and more often.

The region is also moving in the same direction as Europe.

CountryReference frameworkStatus (October 2026)Key deadline
Spain (EU)Cyber Resilience Act, NIS2, ENSCRA: reporting enforceable since 11/09/202624 h early warning (CRA)
MexicoNational Cybersecurity Plan 2025-2030; Cybersecurity BillPlan mandatory for the Federal Public Administration; bill in the SenateUnder 24 h for critical incidents (federal public sector)
ColombiaDecree 338 of 2022; National Cybersecurity Strategy 2025-2027No specific cybersecurity law15 business days (incidents involving personal data)
PeruRegulation of Law 29733 on data protection; SBS Resolution 01741-2026No general cybersecurity law passed48 h (personal data); 24 h (financial sector)
ChileLaw 21.663 Cybersecurity FrameworkIn force, supervised by ANCI3 h early warning

Mexico: National Cybersecurity Plan and a law on the way

Mexico does not yet have a federal cybersecurity law in force. The Cybersecurity Bill was submitted to the Senate on 30 April 2025 and is still going through the process. In August and September 2026 new bills were submitted to create a National Cybersecurity Agency, but none has been passed yet.

Meanwhile, the National Cybersecurity Plan 2025-2030 has been mandatory since December 2025 for the Federal Public Administration. It requires critical incidents to be reported to the National CSIRT in under 24 hours and institutional cybersecurity plans to be drawn up, coordinated by the Digital Transformation and Telecommunications Agency (ATDT). The same 24-hour clock as the CRA.

Colombia: digital governance without a specific law

Colombia does not yet have a cybersecurity law as such. Its framework rests on Decree 338 of 2022, which sets digital security governance and the role of ColCERT as the single point of contact for incidents, and on the National Cybersecurity Strategy 2025-2027.

For companies outside the financial sector, the clearest requirement today is to report incidents affecting personal data within a maximum of 15 business days. Activity is intense: ColCERT handled 697 incidents in 2025.

Peru: shorter deadlines through data protection and the financial sector

Peru does not yet have a general cybersecurity law, although Congress has included it in its 2026-2027 work plan. In the meantime, demanding deadlines already apply through other channels. The new regulation of Law 29733 on data protection, in force since 31 March 2025, requires security incidents to be reported to the authority and to those affected within 48 hours.

In the financial sector, SBS Resolution 01741-2026, published in July 2026, requires banks, savings institutions and financial companies to publicly disclose cybersecurity incidents within 24 hours.

Chile: the most advanced law in the region

Chile led the way with Law 21.663 on the Cybersecurity Framework, inspired by NIS2. It requires essential service operators to send an early warning to ANCI within a maximum of 3 hours of detecting a significant incident, and a full report within 72 hours.

In every case, the conclusion is the same: deadlines measured in hours can only be met with a reliable IT inventory and automated processes.

How to prepare: 5 practical steps

  1. A complete, up-to-date inventory. Without knowing what hardware and software you have, versions included, it is impossible to know whether an alert affects you.
  2. A CMDB with relationships. A list of assets is not enough: you need to know which services depend on each one in order to prioritise.
  3. A vulnerability management procedure. Who receives the alerts, how they are assessed and how quickly measures are applied.
  4. Integration with the security team. Alerts must reach the SOC or SIEM without depending on manual processes.
  5. Communications ready to go. Templates and channels defined to notify users and managers once the 24-hour clock is ticking.

It is worth starting now: harmonised standards for vulnerability management are expected by the end of October 2026, but the reporting obligation does not wait for them.

How Proactivanet helps you comply with the Cyber Resilience Act

Proactivanet turns your IT inventory into the foundation of your cybersecurity strategy. Its Cybersecurity & Compliance solution, powered by the CyberITAM engine, integrates ENS, NIS2 and DORA requirements with the inventory, the CMDB and the Service Desk. And with offices in Spain, Mexico, Colombia, Peru and Chile, we know the regulatory framework of each market first-hand.

  • Discovery & Asset Management: automatically detects up to 110% of physical and virtual assets, with no manual intervention.
  • CMDB: links configuration items and services so you know the impact of a vulnerability instantly.
  • Real-time alerts to the SOC or SIEM via API, so security can act without delay.
  • Multichannel notifications by email, SMS, WhatsApp, Microsoft Teams or Telegram, so nobody finds out too late.
  • Change Management: documents and controls every patch or corrective measure.

When a vendor publishes an alert, the question "does this affect us?" will be answered in minutes, not days.

Frequently asked questions about the Cyber Resilience Act

Since when must vulnerabilities be reported under the Cyber Resilience Act?

Since 11 September 2026, for any actively exploited vulnerability or severe incident the manufacturer becomes aware of from that date onwards.

Who is notified in Spain?

INCIBE-CERT, as coordinating CSIRT, and ENISA, simultaneously and through the Single Reporting Platform.

What is the deadline for the early warning?

24 hours from the moment of awareness. After that, 72 hours for the notification and 14 days (vulnerabilities) or 1 month (incidents) for the final report.

Does the Cyber Resilience Act affect companies that only use software?

The reporting obligation lies with the manufacturer. But those using the products will receive more alerts and need a reliable inventory to know whether they are affected.

Does the Cyber Resilience Act affect Latin American companies?

Yes, if they sell products with digital elements in the EU. And indirectly, all those using software from vendors present in the European market.

Is there a cybersecurity law in Mexico?

There is no federal law in force yet: the bill is in the Senate. The National Cybersecurity Plan 2025-2030 is mandatory for the Federal Public Administration, with critical incidents reported in under 24 hours.

What reporting deadlines apply in Colombia and Peru?

In Colombia, 15 business days for incidents affecting personal data. In Peru, 48 hours for incidents involving personal data and 24 hours in the financial sector.

When will the Cyber Resilience Act apply in full?

On 11 December 2027.

Do you know today how many devices and applications would be affected by the next critical vulnerability? Request a Proactivanet demo and discover how to keep your entire IT estate visible, connected and ready to respond.

Subscribe to our Blog
Loading