CompareHomeAppliances
regulation 2 September 2026

EU Cyber Reporting Rules for Smart Appliances Start 11 September 2026

From 11 September 2026, makers of connected appliances must report actively exploited vulnerabilities and severe incidents through the EU's new Single Reporting Platform within 24 hours.

By CHA News Desk · Updated 2 September 2026

Researched and drafted with AI language-model assistance from cited public sources, per our AI-content disclosure.

The Berlaymont building, European Commission headquarters in Brussels, at sunrise with an EU flag and REPowerEU banner visible.
Photo by Cbliu, CC BY-SA 4.0, via Wikimedia Commons. Shown for illustration.

Manufacturers of internet-connected appliances face their first binding deadline under the EU’s Cyber Resilience Act on 11 September 2026, nine days from now, when mandatory reporting of actively exploited vulnerabilities and severe security incidents begins. The obligation runs through a new EU-wide tool, the Single Reporting Platform, operated by ENISA, the EU’s cybersecurity agency.

Regulation (EU) 2024/2847, the Cyber Resilience Act, entered into force on 10 December 2024. Its Article 14 reporting duties are the first part of the law to become enforceable, well ahead of the CRA’s broader security requirements.

What does the reporting rule actually require?

Once a manufacturer identifies an actively exploited vulnerability or a severe incident affecting a “product with digital elements,” it must submit an early-warning notification to the Single Reporting Platform within 24 hours. A fuller notification follows within 72 hours. After that, the manufacturer owes a final report: within 14 days of a fix becoming available for an actively exploited vulnerability, or within one month of the 72-hour notification for a severe incident.

ENISA’s own page on the platform states plainly what changes on the deadline date: “As of 11 September 2026 onwards, the SRP will be used by CSIRTs and manufacturers for mandatory reporting and could be used by any natural/legal persons for voluntary reporting.” The platform is designed to replace a patchwork of separate national notifications with a single submission, which ENISA then shares with national CSIRTs and market surveillance authorities across every Member State where the affected product is sold.

Does this mean the full Cyber Resilience Act is now in force?

No, and this is the distinction worth getting right. 11 September 2026 activates only the reporting mechanism. The CRA’s substantive security requirements, security-by-design, secure-by-default configuration, a defined period of mandatory security updates, and CE-marking conformity assessment, do not become mandatory until 11 December 2027, more than a year later. Until then, manufacturers must report exploited flaws and serious incidents when they occur, but they are not yet legally required to have built their products to the CRA’s security baseline.

Which appliances are actually covered?

The Commission defines the CRA’s scope broadly: any hardware or software product with a direct or indirect data connection to a device or network. Its own examples run “from baby-monitors to smart watches, from apps to computer programs,” and it explicitly lists household appliances as within the conformity-assessment scope alongside those examples.

In practice that means any appliance a CHA reader might buy with WiFi or a companion app, a smart washing machine that reports cycle status to a phone, a connected fridge with an app-based inventory feature, or a robot vacuum with cloud connectivity, falls under the CRA as a product with digital elements. A basic corded appliance with no network connection does not.

No manufacturer, Bosch, Siemens, LG, Samsung, or Miele among them, has yet published a CRA-compliance statement tied to a specific appliance model. Nothing has yet been reported through the Single Reporting Platform, since the obligation does not start until 11 September.

What should a shopper do with this?

Nothing changes at checkout on 11 September. The immediate effect is regulatory plumbing: manufacturers gain a formal, EU-wide channel and a legal deadline for reporting flaws in connected products. The requirement worth remembering is the later one. If you are buying a smart appliance now, the meaningful CRA milestone for judging its long-term security is 11 December 2027, when built-in security-by-design and guaranteed update periods actually become mandatory, not this month’s reporting start date.

Frequently asked questions

What happens on 11 September 2026 under the Cyber Resilience Act? +

The CRA's Article 14 vulnerability and incident reporting obligations become mandatory. Manufacturers of connected products, including smart appliances, must start reporting actively exploited vulnerabilities and severe incidents through ENISA's Single Reporting Platform.

Does this mean my smart appliance is now more secure? +

Not directly. 11 September 2026 only starts the reporting mechanism. The CRA's main security requirements, such as security-by-design and mandatory security updates, do not become mandatory until 11 December 2027.

Which appliances does the Cyber Resilience Act cover? +

Any 'product with digital elements', meaning hardware or software with a data connection to a device or network. The European Commission names household appliances explicitly within scope, alongside baby monitors, smart watches, and apps. A washing machine, fridge, or robot vacuum with WiFi or a companion app falls under this definition.

Sources

  1. Cyber Resilience Act (European Commission, Digital Strategy)
  2. Single Reporting Platform (SRP) (ENISA)
← All news