Home Bots in Society‘Machine builders must act now ahead of CRA vulnerability reporting deadline Machine’

‘Machine builders must act now ahead of CRA vulnerability reporting deadline Machine’

by Pieter Werner

Mchine builders must act now to prepare for the EU Cyber Resilience Act’s vulnerability and incident reporting requirements, Mitsubishi Electric Europe has warned, with the rules due to take effect on 11 September 2026.

From that date, affected companies selling products with digital elements in the European Union will have to comply with mandatory reporting deadlines for actively exploited vulnerabilities and severe security incidents. The requirements precede the CRA’s main obligations, which will apply from 11 December 2027.

The reporting process involves the European Union Agency for Cybersecurity (ENISA) and relevant cybersecurity incident response teams, with specific actions required within 24 hours, 72 hours and 14 days of an incident.

Frederik Kok, Senior Cyber Security Expert at Mitsubishi Electric Europe, said companies already complying with the EU’s NIS2 Directive may have much of the required reporting infrastructure in place. Other machine builders may need to establish new procedures for identifying, assessing and reporting vulnerabilities and incidents.

“While machine builders who are already compliant with the EU’s NIS2 Directive will be in a strong position to meet the CRA’s vulnerability reporting requirements, many more besides will need to build the necessary reporting capabilities from the ground up,” Kok said.

ENISA is responsible for establishing and operating the CRA Single Reporting Platform, which will be used for reporting under the regulation. The agency has also published information on the reporting obligations and development of the platform.

Mitsubishi Electric is a CVE Numbering Authority, or CNA, within the global Common Vulnerabilities and Exposures programme. This allows the company to assign CVE identifiers to vulnerabilities affecting products within its authorised scope and publish related vulnerability information in a standardised format.

Kok said Mitsubishi Electric intends to use its vulnerability-management experience to support machine builders preparing for the CRA requirements. The company is advising manufacturers to review their reporting procedures before the September deadline.

Misschien vind je deze berichten ook interessant