{"id":35316,"date":"2026-10-07T00:00:21","date_gmt":"2026-10-06T22:00:21","guid":{"rendered":"https:\/\/www.proactivanet.com\/?p=35316"},"modified":"2026-10-07T09:35:26","modified_gmt":"2026-10-07T07:35:26","slug":"cyber-resilience-act","status":"publish","type":"post","link":"https:\/\/www.proactivanet.com\/en\/blog\/security\/cyber-resilience-act\/","title":{"rendered":"Cyber Resilience Act: what changes with the obligation to report vulnerabilities"},"content":{"rendered":"<p>The <strong>Cyber Resilience Act<\/strong> is no longer a distant regulation. Since 11 September 2026, manufacturers of products with digital elements sold in the European Union must report actively exploited vulnerabilities and severe incidents within 24 hours.<\/p>\n<p>It is the first obligation of the regulation that is already enforceable, and it arrives more than a year before full application. In this article we review what changes, who is affected (Spain, Mexico, Colombia, Peru and Chile), which deadlines apply and why the starting point is always the same: knowing exactly what technology you have and where it is.<\/p>\n<h2>What is the Cyber Resilience Act?<\/h2>\n<p>The Cyber Resilience Act (CRA) is Regulation (EU) 2024\/2847. It sets common cybersecurity requirements for every product with digital elements placed on the EU market, whether software or connected hardware.<\/p>\n<p>Its underlying idea is that security should be part of the product from design and throughout its lifecycle, rather than depending on after-the-fact patches. It applies in stages:<\/p>\n<div style=\"overflow-x: auto; margin: 20px 0 32px;\">\n<table style=\"width: 100%; border-collapse: collapse; margin: 0; font-size: 15px; line-height: 1.45; min-width: 560px;\">\n<thead>\n<tr>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">Date<\/th>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">Milestone<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background: #ffffff;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">10 December 2024<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Entry into force of the regulation<\/td>\n<\/tr>\n<tr style=\"background: #EEF3FA;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">11 September 2026<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Obligation to report exploited vulnerabilities and severe incidents (Article 14)<\/td>\n<\/tr>\n<tr style=\"background: #ffffff;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">11 December 2027<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Full application of the remaining requirements, including CE marking<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2>What changes from 11 September 2026<\/h2>\n<p><a href=\"https:\/\/www.cyberresilienceact.eu\/es\/reporting.html\" target=\"_blank\" rel=\"noopener\">Article 14<\/a> requires manufacturers to report two things: any vulnerability in their product that is being actively exploited, and any severe incident affecting its security.<\/p>\n<p>The notification goes simultaneously to ENISA and to the coordinating CSIRT of the country where the manufacturer has its main establishment. In Spain, that CSIRT is INCIBE-CERT. There is a single channel: the Single Reporting Platform (SRP) managed by ENISA, operational from that same date.<\/p>\n<h3>Reporting deadlines<\/h3>\n<div style=\"overflow-x: auto; margin: 20px 0 32px;\">\n<table style=\"width: 100%; border-collapse: collapse; margin: 0; font-size: 15px; line-height: 1.45; min-width: 560px;\">\n<thead>\n<tr>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">Deadline<\/th>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">What must be sent<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background: #ffffff;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">24 hours<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Early warning from the moment of awareness<\/td>\n<\/tr>\n<tr style=\"background: #EEF3FA;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">72 hours<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Notification with the information available<\/td>\n<\/tr>\n<tr style=\"background: #ffffff;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">14 days<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Final report on an exploited vulnerability<\/td>\n<\/tr>\n<tr style=\"background: #EEF3FA;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">1 month<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Final report on a severe incident<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p>In addition, the manufacturer must inform affected users and, where appropriate, indicate measures to mitigate the risk.<\/p>\n<h2>What the Cyber Resilience Act does not yet require (and who it affects)<\/h2>\n<p>The scope of this first phase is narrower than it seems. On 27 July 2026 the European Commission published a <a href=\"https:\/\/www.ecija.com\/actualidad-insights\/cyber-resilience-act-obligaciones-de-notificacion-de-vulnerabilidades-e-incidentes-desde-septiembre-de-2026\/\" target=\"_blank\" rel=\"noopener\">first interpretative guidance<\/a> clarifying several points:<\/p>\n<ul>\n<li><strong>It is not retroactive.<\/strong> Anything the manufacturer already knew before 11 September 2026 does not have to be reported.<\/li>\n<li><strong>Only real exploitation counts.<\/strong> The mere existence of a vulnerability does not trigger the obligation; active exploitation does.<\/li>\n<li><strong>It still applies after end of support.<\/strong> The reporting obligation does not end when the product is no longer supported.<\/li>\n<\/ul>\n<p>The obligation falls on the manufacturer. But the impact also reaches organisations that use those products: they will receive alerts from their vendors far more often and faster, and will only be able to react in time if they know which devices and which software are affected.<\/p>\n<h2>CRA, NIS2 and ENS: pieces of the same puzzle<\/h2>\n<p>The Cyber Resilience Act does not replace other regulations: it complements them. NIS2 and Spain's National Security Framework (ENS) focus on how organisations manage their risks, including supply-chain security. The CRA, by contrast, targets the security of the products that supply chain delivers.<\/p>\n<p>In practice, all three frameworks ask IT teams for the same thing: a reliable inventory, documented vulnerability management and rapid response capability. Those already working this way to comply with NIS2 or the ENS are well on their way.<\/p>\n<h2>What about other countries? Why the CRA matters to you too<\/h2>\n<p>The Cyber Resilience Act applies to every product with digital elements sold in the EU, regardless of where the manufacturer is based. A company from Mexico, Colombia, Peru or Chile selling software or connected devices in Europe has the same reporting obligations from 11 September 2026.<\/p>\n<p>And even if you do not sell in Europe, the CRA affects you as a user. Much of the software used by Latin American organisations comes from vendors operating in the European market, so their vulnerability alerts will arrive sooner and more often.<\/p>\n<p>The region is also moving in the same direction as Europe.<\/p>\n<div style=\"overflow-x: auto; margin: 20px 0 32px;\">\n<table style=\"width: 100%; border-collapse: collapse; margin: 0; font-size: 15px; line-height: 1.45; min-width: 560px;\">\n<thead>\n<tr>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">Country<\/th>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">Reference framework<\/th>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">Status (October 2026)<\/th>\n<th style=\"background: #00A0DF; color: #ffffff; text-align: left; padding: 12px 14px; font-weight: 600; border: 1px solid #00A0DF; vertical-align: top;\">Key deadline<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"background: #ffffff;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">Spain (EU)<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Cyber Resilience Act, NIS2, ENS<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">CRA: reporting enforceable since 11\/09\/2026<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">24 h early warning (CRA)<\/td>\n<\/tr>\n<tr style=\"background: #EEF3FA;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">Mexico<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">National Cybersecurity Plan 2025-2030; Cybersecurity Bill<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Plan mandatory for the Federal Public Administration; bill in the Senate<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Under 24 h for critical incidents (federal public sector)<\/td>\n<\/tr>\n<tr style=\"background: #ffffff;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">Colombia<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Decree 338 of 2022; National Cybersecurity Strategy 2025-2027<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">No specific cybersecurity law<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">15 business days (incidents involving personal data)<\/td>\n<\/tr>\n<tr style=\"background: #EEF3FA;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">Peru<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Regulation of Law 29733 on data protection; SBS Resolution 01741-2026<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">No general cybersecurity law passed<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">48 h (personal data); 24 h (financial sector)<\/td>\n<\/tr>\n<tr style=\"background: #ffffff;\">\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c; font-weight: 600;\">Chile<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">Law 21.663 Cybersecurity Framework<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">In force, supervised by ANCI<\/td>\n<td style=\"padding: 12px 14px; border: 1px solid #D5E0EC; vertical-align: top; color: #2c2c2c;\">3 h early warning<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h3>Mexico: National Cybersecurity Plan and a law on the way<\/h3>\n<p>Mexico does not yet have a federal cybersecurity law in force. The Cybersecurity Bill was submitted to the Senate on 30 April 2025 and is still going through the process. In August and September 2026 new bills were submitted to create a National Cybersecurity Agency, but none has been passed yet.<\/p>\n<p>Meanwhile, the National Cybersecurity Plan 2025-2030 has been mandatory since December 2025 for the Federal Public Administration. It requires critical incidents to be reported to the National CSIRT in under 24 hours and institutional cybersecurity plans to be drawn up, coordinated by the Digital Transformation and Telecommunications Agency (ATDT). The same 24-hour clock as the CRA.<\/p>\n<h3>Colombia: digital governance without a specific law<\/h3>\n<p>Colombia does not yet have a cybersecurity law as such. Its framework rests on Decree 338 of 2022, which sets digital security governance and the role of ColCERT as the single point of contact for incidents, and on the National Cybersecurity Strategy 2025-2027.<\/p>\n<p>For companies outside the financial sector, the clearest requirement today is to report incidents affecting personal data within a maximum of 15 business days. Activity is intense: ColCERT handled 697 incidents in 2025.<\/p>\n<h3>Peru: shorter deadlines through data protection and the financial sector<\/h3>\n<p>Peru does not yet have a general cybersecurity law, although Congress has included it in its 2026-2027 work plan. In the meantime, demanding deadlines already apply through other channels. The new regulation of Law 29733 on data protection, in force since 31 March 2025, requires security incidents to be reported to the authority and to those affected within 48 hours.<\/p>\n<p>In the financial sector, SBS Resolution 01741-2026, published in July 2026, requires banks, savings institutions and financial companies to publicly disclose cybersecurity incidents within 24 hours.<\/p>\n<h3>Chile: the most advanced law in the region<\/h3>\n<p>Chile led the way with Law 21.663 on the Cybersecurity Framework, inspired by NIS2. It requires essential service operators to send an early warning to ANCI within a maximum of 3 hours of detecting a significant incident, and a full report within 72 hours.<\/p>\n<p>In every case, the conclusion is the same: deadlines measured in hours can only be met with a reliable IT inventory and automated processes.<\/p>\n<h2>How to prepare: 5 practical steps<\/h2>\n<ol>\n<li><strong>A complete, up-to-date inventory.<\/strong> Without knowing what hardware and software you have, versions included, it is impossible to know whether an alert affects you.<\/li>\n<li><strong>A CMDB with relationships.<\/strong> A list of assets is not enough: you need to know which services depend on each one in order to prioritise.<\/li>\n<li><strong>A vulnerability management procedure.<\/strong> Who receives the alerts, how they are assessed and how quickly measures are applied.<\/li>\n<li><strong>Integration with the security team.<\/strong> Alerts must reach the SOC or SIEM without depending on manual processes.<\/li>\n<li><strong>Communications ready to go.<\/strong> Templates and channels defined to notify users and managers once the 24-hour clock is ticking.<\/li>\n<\/ol>\n<p>It is worth starting now: harmonised standards for vulnerability management are expected by the end of October 2026, but the reporting obligation does not wait for them.<\/p>\n<h2>How Proactivanet helps you comply with the Cyber Resilience Act<\/h2>\n<p>Proactivanet turns your IT inventory into the foundation of your cybersecurity strategy. Its <a href=\"https:\/\/www.proactivanet.com\/en\/discovery-it-asset-management\/cyberitam\/\"><strong>Cybersecurity &amp; Compliance<\/strong><\/a> solution, powered by the CyberITAM engine, integrates ENS, NIS2 and DORA requirements with the inventory, the CMDB and the Service Desk. And with offices in Spain, Mexico, Colombia, Peru and Chile, we know the regulatory framework of each market first-hand.<\/p>\n<ul>\n<li><a href=\"https:\/\/www.proactivanet.com\/en\/discovery-it-asset-management\/\"><strong>Discovery &amp; Asset Management:<\/strong><\/a> automatically detects up to 110% of physical and virtual assets, with no manual intervention.<\/li>\n<li><a href=\"https:\/\/www.proactivanet.com\/en\/configuration-management-cmdb\/\"><strong>CMDB:<\/strong><\/a> links configuration items and services so you know the impact of a vulnerability instantly.<\/li>\n<li><strong>Real-time alerts to the SOC or SIEM<\/strong> via API, so security can act without delay.<\/li>\n<li><strong>Multichannel notifications<\/strong> by email, SMS, WhatsApp, Microsoft Teams or Telegram, so nobody finds out too late.<\/li>\n<li><strong>Change Management:<\/strong> documents and controls every patch or corrective measure.<\/li>\n<\/ul>\n<p>When a vendor publishes an alert, the question \"does this affect us?\" will be answered in minutes, not days.<\/p>\n<h2>Frequently asked questions about the Cyber Resilience Act<\/h2>\n<h3>Since when must vulnerabilities be reported under the Cyber Resilience Act?<\/h3>\n<p>Since 11 September 2026, for any actively exploited vulnerability or severe incident the manufacturer becomes aware of from that date onwards.<\/p>\n<h3>Who is notified in Spain?<\/h3>\n<p>INCIBE-CERT, as coordinating CSIRT, and ENISA, simultaneously and through the Single Reporting Platform.<\/p>\n<h3>What is the deadline for the early warning?<\/h3>\n<p>24 hours from the moment of awareness. After that, 72 hours for the notification and 14 days (vulnerabilities) or 1 month (incidents) for the final report.<\/p>\n<h3>Does the Cyber Resilience Act affect companies that only use software?<\/h3>\n<p>The reporting obligation lies with the manufacturer. But those using the products will receive more alerts and need a reliable inventory to know whether they are affected.<\/p>\n<h3>Does the Cyber Resilience Act affect Latin American companies?<\/h3>\n<p>Yes, if they sell products with digital elements in the EU. And indirectly, all those using software from vendors present in the European market.<\/p>\n<h3>Is there a cybersecurity law in Mexico?<\/h3>\n<p>There is no federal law in force yet: the bill is in the Senate. The National Cybersecurity Plan 2025-2030 is mandatory for the Federal Public Administration, with critical incidents reported in under 24 hours.<\/p>\n<h3>What reporting deadlines apply in Colombia and Peru?<\/h3>\n<p>In Colombia, 15 business days for incidents affecting personal data. In Peru, 48 hours for incidents involving personal data and 24 hours in the financial sector.<\/p>\n<h3>When will the Cyber Resilience Act apply in full?<\/h3>\n<p>On 11 December 2027.<\/p>\n<p>Do you know today how many devices and applications would be affected by the next critical vulnerability? <a href=\"https:\/\/www.proactivanet.com\/en\/discovery-it-asset-management\/cyberitam\/?utm_source=blog&amp;utm_medium=cta&amp;utm_campaign=cyber-resilience-act&amp;utm_content=en\"><strong>Request a Proactivanet demo<\/strong><\/a> and discover how to keep your entire IT estate visible, connected and ready to respond.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Cyber Resilience Act is no longer a distant regulation. Since...  <\/p>\n<div class=\"read-more mt-4 text-blue text-xs\"><\/div>\n","protected":false},"author":7,"featured_media":35324,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1930,1856,1497],"tags":[2013,2014,2016,2015,2018,2017,1466],"class_list":["post-35316","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ciberseguridad","category-compliance-13-quick-steps-to-meet-the-most-demanding-security-frameworks","category-security","tag-vulnerability-management","tag-cyber-resilience-act","tag-nis2","tag-cra","tag-compliance","tag-ens","tag-cybersecurity"],"acf":{"is_icon":""},"post_mailing_queue_ids":[],"_links":{"self":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts\/35316","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/comments?post=35316"}],"version-history":[{"count":5,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts\/35316\/revisions"}],"predecessor-version":[{"id":35383,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/posts\/35316\/revisions\/35383"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/media\/35324"}],"wp:attachment":[{"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/media?parent=35316"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/categories?post=35316"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.proactivanet.com\/en\/wp-json\/wp\/v2\/tags?post=35316"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}