New reporting requirements for manufacturers of digital products from 11 September 2026

When the obligation to report vulnerabilities in connected devices comes into force on 11 September, a number of companies will find themselves “caught out”. That is the assessment of Matthias Springer, Senior Vice President of Functional Safety & Security at TÜV NORD. From this date onwards, all companies must report any vulnerabilities discovered in their connected products to a central authority within 24 hours and provide solutions to rectify them. If they fail to do so, they risk substantial fines. Companies can significantly reduce these liability risks by having their crisis management processes assessed: The assessment simulates the process, identifies critical paths or deviations, and thereby identifies areas for improvement.
Whether it’s a cycle computer with a Bluetooth interface, a vacuum cleaner or a machine on the production line: until now, manufacturers have been able to take action on their own initiative when vulnerabilities in their products were discovered, without having to meet any deadlines. In future, they will have to respond within 24 hours and report the incident to the European Union Agency for Cybersecurity (ENISA). The agency collects the reports and publishes them. However, these entries will not be deleted; once published, vulnerabilities will remain visible to everyone. This is stipulated by the provisions of the Cyber Resilience Act, which will come into force on 11 September 2026. This could lead to reputational damage if a company is frequently listed there.
Manufacturers must notify ENISA of products affected by vulnerabilities, specify the nature of the vulnerability, classify its severity and propose solutions to rectify the problem. If they fail to do so, they risk substantial fines. The challenge, according to Mr Springer, is that this reporting requirement also applies to purchased components or software. As a result, companies need a coordinating function to manage vulnerabilities. Companies that have established processes to be followed in the event of a crisis are on the safe side. Ideally, they already have a certified management system in accordance with ISO/IEC 27001 or IEC 62443-4-1, which provide an excellent basis for vulnerability management. However, there is no specific standard for vulnerability management itself, which makes matters difficult for manufacturers, particularly given that the processes must be “in place” by 11 September.
This is precisely where service providers such as TÜV NORD come into play: they can evaluate the defined processes – in other words, check whether responsibilities are clearly defined, whether resource management is in order, and whether the procedural approach as such is coherent. “Our assessment analyses precisely these processes and interfaces,” says Mr Springer. “We have been addressing the issue of cyber security since the 1990s, and we have been certifying to the IEC 62443 series for almost ten years.” Around 70 specialists work at TÜV NORD in this field, over 40 of whom are based in Germany. During an assessment, all processes and associated documents are analysed. Where appropriate, opportunities for improvement are identified in the final technical report. This provides manufacturers with evidence that the implemented process functions reliably and in compliance with requirements. However, different providers of such assessments may prioritise different aspects. “Here at TÜV NORD, we are awaiting the publication of the harmonised standard and, in the meantime, are working in accordance with the standards that ENISA is due to publish as the intended harmonised standards. This ensures we remain at the cutting edge.”
Founded over 150 years ago, we stand for security and trust worldwide. As a knowledge company, we have our sights firmly set on the digital future. Whether engineers, IT security experts or specialists for the mobility of the future: in more than 100 countries, we ensure that our customers become even more successful in the networked world.