IT Brief Ireland - Technology news for CIOs & IT decision-makers
Ireland
EU cyber rules test manufacturers' reporting readiness

EU cyber rules test manufacturers' reporting readiness

Thu, 10th Sep 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Finite State said manufacturers using its platform are prepared for the European Union Cyber Resilience Act reporting obligations. The first incident reporting requirement takes effect with a 24-hour notification window for actively exploited vulnerabilities.

For many device makers, the main challenge is not filing a report but deciding whether one is required. Under the rules, manufacturers must determine whether a vulnerability is present in a product they shipped, whether it is being actively exploited, and whether the vulnerable code is reachable in that product.

The requirement applies across a wide range of connected products, including home routers, consumer electronics, industrial controllers, medical devices, software, and connected vehicles. It also covers products that remain under support, even if they were shipped years before the rules took effect.

Once a manufacturer determines that one of its products contains a vulnerability that is being actively exploited, it has 24 hours to notify the EU Agency for Cybersecurity and a designated national computer security incident response team through the bloc's single reporting system. A more detailed submission must follow within 72 hours, with a final report due within 14 days after a mitigation becomes available.

That timeline puts pressure on internal product security teams because the countdown starts only after a manufacturer concludes that its own product is affected. Companies therefore need evidence showing what software and components are inside each product version and whether the vulnerable function can actually run.

Visibility problem

For many manufacturers, gathering that evidence quickly is difficult. Modern connected devices often contain software built up over years of releases, with code supplied by third parties and components delivered without source code.

Finite State said its system analyses compiled firmware to rebuild an inventory of what is inside a shipped build, including third-party components, and records whether vulnerable functions can execute. That allows customers to identify affected products already on the market within minutes when a newly exploited flaw emerges.

The broader compliance issue goes beyond speed. Most products covered by the Cyber Resilience Act are self-assessed, meaning the manufacturer's own records support any notification sent to regulators and any explanation later requested by customers or authorities.

If a company cannot back its filing with evidence, the commercial consequences could be serious because access to the European market depends on meeting the rules. That makes software bills of materials, vulnerability records, and internal documentation central to regulatory compliance rather than optional security paperwork.

Doc McConnell, Head of Policy and Compliance at Finite State, said the reporting timeline can be misunderstood because it does not begin when a vulnerability is first made public.

"The clock does not start when a vulnerability is published. The clock starts when a manufacturer determines that its own product is affected and that someone is exploiting the flaw, and that determination is a judgment call made under time pressure," said McConnell.

"Making that call well requires an accurate picture of what is inside the product and whether the vulnerable code can run there. Without that picture, reporting becomes a scramble to reconstruct facts you should already have," McConnell said.

Customer example

Finite State cited Quectel Wireless Solutions, which has used the company for independent testing since 2023. The IoT supplier said that preparing early has left it in a stronger position as the reporting obligations begin.

"We started this work before any regulator asked us to, and that head start is why we're ready for September 11," said Omar Aamer, Cybersecurity Compliance Manager at Quectel Wireless Solutions.

"When an enterprise customer or an authority asks what is inside a module and what we decided about it, we produce the document rather than the promise," Aamer said.

The compliance burden is unlikely to end with the first reporting milestone. Further obligations under the Cyber Resilience Act will introduce broader cybersecurity requirements and a more extensive technical documentation package, increasing the need for detailed product records.

Those records also overlap with other regulatory and industry frameworks outside the EU. Manufacturers selling into sectors such as healthcare, automotive, and industrial systems increasingly face similar questions from regulators and customers about software composition, known vulnerabilities, and the steps taken to address them.

As a result, the immediate issue raised by the new EU rules is not only whether companies can submit an incident notice within 24 hours. It is whether they have already built the internal evidence needed to decide, under pressure, whether they must report at all.