Under the Cyber Resilience Act, manufacturers have 24 hours to report an actively exploited vulnerability in their product. See how GitLab helps you answer fast.

EU Cyber Resilience Act reporting starts on 11 September 2026: 24h alert, 72h notification, 14-day report. Not a legal memo: the pipeline runbook, with SBOM in CI, govulncheck and…

Starting Friday, businesses operating in the EU will have 24 hours to notify the government any time they discover serious product security incidents.