A Community Guide to the EU CRA September 11 Deadline for Manufacturers
Cybersecurity Classified by Officially
By Madalin Neag, Sally Cooper, and Steve Winslow
If you are a maintainer, steward, or manufacturer, you might have heard about the EU Cyber Resilience Act (CRA) and wondered how it impacts your day-to-day work. The CRA requirements for Stewards do not take effect until December 11, 2027, but the requirements for Manufacturers take effect today, on September 11, 2026.
The CRA introduces new cybersecurity requirements for products with digital elements, with responsibilities that differ across the software ecosystem. Most of the open source software community will qualify under the CRA’s Steward framework, but knowing how the CRA will impact your downstream commercial ecosystem, who will be classified as Manufacturers, will be important. For the open source community, understanding how manufacturers will interact with open source projects is an important part of preparing for the next phase of CRA implementation.
An important milestone for this shared security model is fast approaching. On September 11, 2026, the CRA’s mandatory reporting requirements apply for manufacturers. This article explains what that means for manufacturers and, importantly, how open source projects and stewards can be ready to support and collaborate with manufacturers when reported vulnerabilities involve open source components.
Why is the September 11, 2026 Deadline Important?
On September 11, 2026, manufacturers are required to begin reporting actively exploited vulnerabilities and severe incidents impacting the security of their products with digital elements.
Once a manufacturer becomes aware of such an event, it must report through the CRA Single Reporting Platform (SRP), with an early warning within 24 hours and a full notification within 72 hours. A final report is then required no later than 14 days after a corrective or mitigating measure becomes available for an AEV, and within one month of the 72-hour notification for a severe incident.
This is an extract. The publication continues at the source.
Read the original at the source: https://openssf.org/blog/2026/09/11/a-community-guide-to-the-eu-cra-september-11-deadline-for-manufacturers/
Officially imported this from Open Source Security Foundation’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Open Source Security Foundation — imported from official source
- Official source
- https://openssf.org/feed/ RSS
- Imported
- September 18, 2026 11:34
- Versions
- 1 recorded
- Identity
https://openssf.org/?p=11744