Europe's 24-Hour Rule Kicks In: Machine Builders Face a New Cyber Reporting Clock
Published on 10/08/2026 at 20:51 | Editorial boerse-global.de
Industrial equipment makers across the European Union woke up on 11 September 2026 to a legal obligation that many are nowhere near ready to meet. From that date, the first binding provisions of the Cyber Resilience Act took effect, and with them a central reporting platform run by the EU's cybersecurity agency began accepting notifications.
Manufacturers of digital products — a group that sweeps in a large slice of the machinery and plant engineering sector — must now report actively exploited vulnerabilities and serious security incidents through that platform. The agency passes the information on to national bodies, including Germany's Federal Office for Information Security (BSI).
Tight deadlines, one reporting channel
Under Article 11 of the regulation, the clock starts the moment a manufacturer learns of a problem. An early warning must reach authorities and the relevant response team within 24 hours. A detailed follow-up report is due within 72 hours, and a final report no later than 14 days after the issue has been remedied. For particularly severe incidents, that final deadline stretches to one month.
The scope is broad: nearly every product with digital elements falls under the rules. In industrial settings that means programmable logic controllers, human-machine interfaces, industrial gateways and remote maintenance access systems, among others.
Non-compliance carries real weight. Beyond a possible ban from the market, the regulation provides for fines of up to €15 million or up to 2.5 percent of worldwide annual turnover.
Survey data exposes a preparedness gap
Short deadlines are only part of the problem. In day-to-day operations, manufacturers are tripping over unclear firmware versions on customers' installed machines and poorly documented internal processes — both of which make hitting the reporting windows difficult. Recent surveys suggest the shortfall is widespread.
A PwC study of 100 German industrial companies with digital products found that 50 percent have no dedicated external reporting channel. Another 27 percent of those surveyed said they had no internal process at all for product-related security incidents. Separate research by the provider Komplyzen, covering 237 software manufacturers in the German-speaking region, found that 85 percent lacked any identifiable reporting route. Just 14 of those manufacturers had an explicit point of contact for security questions.
What comes next — and where help is available
These notification duties are only the opening phase. The Cyber Resilience Act applies in full from 11 December 2027. From that date, no new digital products may be placed on the EU market without a declaration of conformity and CE marking. The regulation will then also require continuous vulnerability management and, among other things, detailed software bills of materials.
Other obligations are stacking up in parallel. On 20 January 2027, the European Machinery Regulation replaces the existing directive, bringing additional requirements for tamper protection and for documenting software changes in mechanical engineering.
Small and medium-sized businesses can seek support during the transition. Since the start of October, a call for proposals under a European programme has been open, allowing companies to apply for financial grants covering gap analyses, risk assessments and testing procedures.
