Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.

Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.

September 10, 2026

Organizations that do business in the European Union (EU) will now have to report product security issues quickly and diligently or face steep penalties.

The EU's Cyber Resilience Act (CRA) possesses a variety of regulations that won't be strictly enforced until December 2027. Organizations have plenty of time to make sure they meet the EU's requirements around, for example, software bills of material (SBOMs), vulnerability handling processes, risk assessments, and other aspects. However, as if to highlight its singular significance, the EU has fast-tracked a particular chunk of the CRA, so that it will come into effect more than a year before everything else.