{"id":9221,"date":"2026-10-01T08:48:57","date_gmt":"2026-10-01T08:48:57","guid":{"rendered":"https:\/\/intnews.it\/?p=9221"},"modified":"2026-10-01T09:50:58","modified_gmt":"2026-10-01T09:50:58","slug":"cyber-resilience-act-article-14-who-must-report","status":"publish","type":"post","link":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/","title":{"rendered":"\u00a0Cyber Resilience Act, Article 14: Who Must Report"},"content":{"rendered":"\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<iframe width=\"100%\" height=\"100%\"src=\"https:\/\/iframe.mediadelivery.net\/embed\/511677\/5a7f2904-9526-440b-ab43-cce41cfcff41\" loading=\"lazy\" allow=\"accelerometer;gyroscope;encrypted-media;picture-in-picture;\" allowfullscreen=\"true\"><\/iframe>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>From 11 September 2026, anyone manufacturing an IP camera, a home router, an industrial PLC or connected software must report actively exploited vulnerabilities to ENISA and their national CSIRT within 24 hours. This is Article 14 of the Cyber Resilience Act, the first binding obligation of the regulation, arriving fifteen months ahead of everything else.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">What Article 14 actually requires<\/h2>\n\n\n\n<p>The Cyber Resilience Act, Regulation (EU) 2024\/2847, takes full effect on 11 December 2027. But Article 14, the reporting obligation, applies from 11 September 2026. It covers &#8220;manufacturers of products with digital elements&#8221;: any hardware or software that connects, directly or indirectly, to a device or network.<\/p>\n\n\n\n<p>The duty is triggered in two cases:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Actively exploited vulnerability<\/strong>: reliable evidence that a malicious actor has exploited it in a system without the owner&#8217;s permission.<\/li>\n\n\n\n<li><strong>Severe incident<\/strong>: a cybersecurity event affecting the manufacturer&#8217;s development, production or maintenance processes in a way that raises risk for users.<\/li>\n<\/ul>\n\n\n\n<p>The timeline runs in three stages, and this is where most secondary sources oversimplify:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th class=\"has-text-align-left\" data-align=\"left\">Stage<\/th><th class=\"has-text-align-left\" data-align=\"left\">Deadline<\/th><th class=\"has-text-align-left\" data-align=\"left\">What it contains<\/th><\/tr><\/thead><tbody><tr><td>Early warning<\/td><td>24 hours from awareness<\/td><td>Minimal notification: an exploited vulnerability exists, which member states the product is sold in. No root cause or fix required yet<\/td><\/tr><tr><td>Notification<\/td><td>72 hours from awareness<\/td><td>General nature of the vulnerability or incident, initial assessment, corrective measures taken or available<\/td><\/tr><tr><td>Final report<\/td><td>14 days <strong>from when a corrective measure becomes available<\/strong> (vulnerabilities) \u2014 one month from the 72-hour notification (severe incidents)<\/td><td>Full description, severity, impact, remediation applied<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p>The detail most guides get wrong: the vulnerability final report doesn&#8217;t run from discovery, it runs from remedy availability. A team that sets a &#8220;day 14 from awareness&#8221; reminder risks filing empty against a deadline that doesn&#8217;t exist yet, or missing the real one if the fix arrives late.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Who is actually affected not just smart-home gadgets<\/h2>\n\n\n\n<p>The dominant narrative around the CRA is &#8220;it&#8217;s about smart home devices.&#8221; That&#8217;s only partly true, and it&#8217;s the least interesting part for a professional Italian reader.<\/p>\n\n\n\n<p><strong>Video surveillance.<\/strong> Connected IP cameras fall under &#8220;Important Class I products&#8221; in Annex III the same risk tier as smart locks, baby monitors and alarm systems, explicitly named as higher-risk consumer products in the regulation&#8217;s recitals. For an installer or system integrator selling cameras to a condominium or a business client, this means having a live-exploit detection process ready now, not built after the first missed notification.<\/p>\n\n\n\n<p><strong>Industrial automation.<\/strong> PLCs, SCADA systems, and computerised numeric controllers for machine tools fall under Industrial Automation &amp; Control Systems (IACS) as listed in Annex III. The practical problem here differs from consumer IoT: on a factory floor, an automatic update can halt a production line, so the regulation itself allows exceptions to automatic updating in critical industrial environments but it does not exempt anyone from the 24-hour reporting duty.<\/p>\n\n\n\n<p><strong>Products already sold.<\/strong> And this is the detail that surprises people most: the obligation also covers products placed on the market before the regulation existed, as long as they remain in use and under active support. A manufacturer no longer actively developing a 2021 camera model, but still supporting units installed at active client sites, must still report an exploited vulnerability found in it. The regulation doesn&#8217;t distinguish &#8220;new CRA-compliant product&#8221; from &#8220;legacy product&#8221; it distinguishes a product still in use from one that&#8217;s been discontinued.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The practical problem: the platform isn&#8217;t ready<\/h2>\n\n\n\n<p>Here&#8217;s the freshest, most concrete fact in this piece. Reports go through ENISA&#8217;s Single Reporting Platform (SRP) a single electronic notification point meant to simultaneously reach ENISA and the designated coordinating national CSIRT. Days before the obligation took effect, the platform had no published web address, no submission API at launch, and according to ENISA&#8217;s own technical guidance, its 72-hour counter can display a report as overdue before 72 hours have actually elapsed since awareness.<\/p>\n\n\n\n<p>For an Italian company, this means one very concrete thing: the legal obligation exists from day one, but the tool for complying with it is still being finished. That&#8217;s not a reason to delay internal preparation it&#8217;s a reason not to blindly trust the platform&#8217;s displayed countdown, and to log internally the exact moment of &#8220;awareness,&#8221; which is the actual legal starting point of the clock.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">The Commission&#8217;s 27 July 2026 guidance<\/h2>\n\n\n\n<p>On 27 July 2026, the European Commission published non-binding application guidance, required under Article 26 of the regulation document <strong>C(2026) 5252<\/strong>, roughly 80 pages. Its most useful contribution defines &#8220;awareness&#8221;: the clock doesn&#8217;t start when a raw report arrives, but once, after a prompt initial assessment, there is &#8220;a reasonable degree of certainty&#8221; that the vulnerability is actually being exploited. It&#8217;s a short but real triage window not an excuse to stall, nor an automatic trigger at the first unverified suspicion.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Italy note<\/h2>\n\n\n\n<p>We&#8217;re keeping this article&#8217;s Italian section focused on why the readiness gap matters for Italian manufacturers and integrators rather than duplicating regulatory detail already covered above; a fuller breakdown of the Italian coordinating authority appears in the Italian version, pending verification of ACN&#8217;s exact coordinating role.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">FAQ<\/h2>\n\n\n\n<p><strong>What happens if a company misses the 24-hour deadline?<\/strong><br>The regulation provides for fines of up to \u20ac15 million or 2.5% of worldwide annual turnover for manufacturer obligation breaches, including Article 14 .<\/p>\n\n\n\n<p><strong>Does this cover vulnerabilities that haven&#8217;t been exploited yet?<\/strong><br>No. Article 14 only triggers for vulnerabilities with reliable evidence of active exploitation by a malicious actor, or for severe incidents. A vulnerability found through good-faith research or a bug bounty programme, with no evidence of exploitation, is not subject to the reporting duty.<\/p>\n\n\n\n<p><strong>Does a product sold in 2022 count?<\/strong><br>Yes, if it&#8217;s still in use and under active manufacturer support. The regulation makes no time-based exemption for the reporting obligation.<\/p>\n\n\n\n<div style=\"height:50px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<p><a href=\"http:\/\/cyberresilienceact.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">cyberresilienceact.eu<\/a>, independent Article 14 summary, updated 7 September 2026<\/p>\n\n\n\n<p>Regulation (EU) 2024\/2847 of the European Parliament and of the Council, 23 October 2024 (EUR-Lex)<\/p>\n\n\n\n<p>European Commission, application guidance C(2026) 5252, 27 July 2026 (<a href=\"http:\/\/digital-strategy.ec.europa.eu\/\" target=\"_blank\" rel=\"noreferrer noopener\">digital-strategy.ec.europa.eu<\/a>)<\/p>\n\n\n\n<p>ComplexDiscovery, &#8220;Cyber Resilience Act reporting starts Sept. 11 on an unfinished platform,&#8221; September 2026<\/p>\n","protected":false},"excerpt":{"rendered":"<p>From 11 September 2026, anyone manufacturing an IP camera, a home router, an industrial PLC or connected software must report actively exploited vulnerabilities to ENISA and their national CSIRT within&#8230;<\/p>\n","protected":false},"author":6,"featured_media":9219,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[132,79,84],"tags":[],"class_list":{"0":"post-9221","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cybereview-en","8":"category-sections","9":"category-technologies"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Cyber Resilience Act, Article 14: Who Must Report<\/title>\n<meta name=\"description\" content=\"From 11 September 2026, manufacturers must report exploited vulnerabilities in 24h, 72h and 14 days. Who is actually in scope, from IoT to industrial control.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cyber Resilience Act, Article 14: Who Must Report\" \/>\n<meta property=\"og:description\" content=\"From 11 September 2026, manufacturers must report exploited vulnerabilities in 24h, 72h and 14 days. Who is actually in scope, from IoT to industrial control.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/\" \/>\n<meta property=\"og:site_name\" content=\"INT News\" \/>\n<meta property=\"article:published_time\" content=\"2026-10-01T08:48:57+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-10-01T09:50:58+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/intnews.it\/wp-content\/uploads\/2026\/09\/cyber-resilience-act.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"author\" content=\"Redazione\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Redazione\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/\"},\"author\":{\"name\":\"Redazione\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#\\\/schema\\\/person\\\/348bf8ca8793a1fff502097a042cb621\"},\"headline\":\"\u00a0Cyber Resilience Act, Article 14: Who Must Report\",\"datePublished\":\"2026-10-01T08:48:57+00:00\",\"dateModified\":\"2026-10-01T09:50:58+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/\"},\"wordCount\":1006,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/intnews.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cyber-resilience-act.webp\",\"articleSection\":[\"Cybereview\",\"Sections\",\"Technologies\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/\",\"url\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/\",\"name\":\"Cyber Resilience Act, Article 14: Who Must Report\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/intnews.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cyber-resilience-act.webp\",\"datePublished\":\"2026-10-01T08:48:57+00:00\",\"dateModified\":\"2026-10-01T09:50:58+00:00\",\"description\":\"From 11 September 2026, manufacturers must report exploited vulnerabilities in 24h, 72h and 14 days. Who is actually in scope, from IoT to industrial control.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#primaryimage\",\"url\":\"https:\\\/\\\/intnews.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cyber-resilience-act.webp\",\"contentUrl\":\"https:\\\/\\\/intnews.it\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/cyber-resilience-act.webp\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/cyber-resilience-act-article-14-who-must-report\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/intnews.it\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"\u00a0Cyber Resilience Act, Article 14: Who Must Report\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/intnews.it\\\/en\\\/\",\"name\":\"INT News\",\"description\":\"innovation tomorrow\",\"publisher\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#organization\"},\"alternateName\":\"Innovation Tomorrow\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/intnews.it\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#organization\",\"name\":\"INT News\",\"alternateName\":\"Innovation Tomorrow\",\"url\":\"https:\\\/\\\/intnews.it\\\/en\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/intnews.it\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/int-logo2.webp\",\"contentUrl\":\"https:\\\/\\\/intnews.it\\\/wp-content\\\/uploads\\\/2023\\\/10\\\/int-logo2.webp\",\"width\":538,\"height\":232,\"caption\":\"INT News\"},\"image\":{\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/intnews.it\\\/en\\\/#\\\/schema\\\/person\\\/348bf8ca8793a1fff502097a042cb621\",\"name\":\"Redazione\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f2ed8a7892d41b1e1987f89dec08d9f4fd49c9b52e56b298a375a6418002ff84?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f2ed8a7892d41b1e1987f89dec08d9f4fd49c9b52e56b298a375a6418002ff84?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/f2ed8a7892d41b1e1987f89dec08d9f4fd49c9b52e56b298a375a6418002ff84?s=96&d=mm&r=g\",\"caption\":\"Redazione\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cyber Resilience Act, Article 14: Who Must Report","description":"From 11 September 2026, manufacturers must report exploited vulnerabilities in 24h, 72h and 14 days. Who is actually in scope, from IoT to industrial control.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/","og_locale":"en_US","og_type":"article","og_title":"Cyber Resilience Act, Article 14: Who Must Report","og_description":"From 11 September 2026, manufacturers must report exploited vulnerabilities in 24h, 72h and 14 days. Who is actually in scope, from IoT to industrial control.","og_url":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/","og_site_name":"INT News","article_published_time":"2026-10-01T08:48:57+00:00","article_modified_time":"2026-10-01T09:50:58+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/intnews.it\/wp-content\/uploads\/2026\/09\/cyber-resilience-act.webp","type":"image\/webp"}],"author":"Redazione","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Redazione","Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#article","isPartOf":{"@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/"},"author":{"name":"Redazione","@id":"https:\/\/intnews.it\/en\/#\/schema\/person\/348bf8ca8793a1fff502097a042cb621"},"headline":"\u00a0Cyber Resilience Act, Article 14: Who Must Report","datePublished":"2026-10-01T08:48:57+00:00","dateModified":"2026-10-01T09:50:58+00:00","mainEntityOfPage":{"@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/"},"wordCount":1006,"commentCount":0,"publisher":{"@id":"https:\/\/intnews.it\/en\/#organization"},"image":{"@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#primaryimage"},"thumbnailUrl":"https:\/\/intnews.it\/wp-content\/uploads\/2026\/09\/cyber-resilience-act.webp","articleSection":["Cybereview","Sections","Technologies"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/","url":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/","name":"Cyber Resilience Act, Article 14: Who Must Report","isPartOf":{"@id":"https:\/\/intnews.it\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#primaryimage"},"image":{"@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#primaryimage"},"thumbnailUrl":"https:\/\/intnews.it\/wp-content\/uploads\/2026\/09\/cyber-resilience-act.webp","datePublished":"2026-10-01T08:48:57+00:00","dateModified":"2026-10-01T09:50:58+00:00","description":"From 11 September 2026, manufacturers must report exploited vulnerabilities in 24h, 72h and 14 days. Who is actually in scope, from IoT to industrial control.","breadcrumb":{"@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#primaryimage","url":"https:\/\/intnews.it\/wp-content\/uploads\/2026\/09\/cyber-resilience-act.webp","contentUrl":"https:\/\/intnews.it\/wp-content\/uploads\/2026\/09\/cyber-resilience-act.webp","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/intnews.it\/en\/cyber-resilience-act-article-14-who-must-report\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/intnews.it\/en\/"},{"@type":"ListItem","position":2,"name":"\u00a0Cyber Resilience Act, Article 14: Who Must Report"}]},{"@type":"WebSite","@id":"https:\/\/intnews.it\/en\/#website","url":"https:\/\/intnews.it\/en\/","name":"INT News","description":"innovation tomorrow","publisher":{"@id":"https:\/\/intnews.it\/en\/#organization"},"alternateName":"Innovation Tomorrow","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/intnews.it\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/intnews.it\/en\/#organization","name":"INT News","alternateName":"Innovation Tomorrow","url":"https:\/\/intnews.it\/en\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/intnews.it\/en\/#\/schema\/logo\/image\/","url":"https:\/\/intnews.it\/wp-content\/uploads\/2023\/10\/int-logo2.webp","contentUrl":"https:\/\/intnews.it\/wp-content\/uploads\/2023\/10\/int-logo2.webp","width":538,"height":232,"caption":"INT News"},"image":{"@id":"https:\/\/intnews.it\/en\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/intnews.it\/en\/#\/schema\/person\/348bf8ca8793a1fff502097a042cb621","name":"Redazione","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/f2ed8a7892d41b1e1987f89dec08d9f4fd49c9b52e56b298a375a6418002ff84?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/f2ed8a7892d41b1e1987f89dec08d9f4fd49c9b52e56b298a375a6418002ff84?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f2ed8a7892d41b1e1987f89dec08d9f4fd49c9b52e56b298a375a6418002ff84?s=96&d=mm&r=g","caption":"Redazione"}}]}},"_links":{"self":[{"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/posts\/9221","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/comments?post=9221"}],"version-history":[{"count":1,"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/posts\/9221\/revisions"}],"predecessor-version":[{"id":9222,"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/posts\/9221\/revisions\/9222"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/media\/9219"}],"wp:attachment":[{"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/media?parent=9221"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/categories?post=9221"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/intnews.it\/en\/wp-json\/wp\/v2\/tags?post=9221"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}