Analyzing critical legal trends and developments across data, cyber, AI and digital regulations from around the world and beyond borders

A new EU regulation requires all companies that provide software, as of 11 September 2026, to report actively exploited vulnerabilities and other security incidents to a designated governmental authority and to users. Breaches of this reporting obligation may result in fines of up to EUR 15 million or 2.5% of the global turnover, whichever is higher.

The security of software and other products with digital components is a rapidly growing challenge. The global number of software vulnerabilities disclosed annually rose from 6,708 in 2005 to 48,244 in 2025, which averages out to 132 newly reported vulnerabilities per day.

At the same time, the threat landscape has become increasingly severe. Cybercrime is now conducted by highly professionalized criminal organizations operating through sophisticated divisions of labor and has evolved into a multi-billion-euro industry. These organizations are increasingly using artificial intelligence to identify vulnerabilities and, within the next few months, are expected to deploy autonomous AI agents to automate cybercrime almost entirely. State actors, too, will increasingly use AI agents, particularly for sabotage purposes.

New regulation aims to improve security

The EU Cyber Resilience Act is the first legislation in the European Union to comprehensively regulate the security of software and other products with digital elements, such as mobile phones and smart home devices. It is intended to make a significant contribution to strengthening the resilience of European society against growing cyber threats.

Free app providers also subject to regulation

The Cyber Resilience Act imposes obligations on manufacturers, importers, and distributors of software and other products with digital elements. However, the new regulation does not apply solely to the software industry. Rather, it covers all companies that provide software to anyone other than their own employees. Since it is irrelevant whether a fee is charged for the software, the regulation also applies to companies that make apps available to their customers free of charge.

Reporting obligations relating to vulnerabilities

As of 11 September, all regulated manufacturers are subject to new reporting obligations. If a manufacturer becomes aware that its software or product contains a vulnerability that is being actively exploited, it must take action within very short timeframes and notify both a government-designated computer security incident response team and the EU Agency for Cybersecurity (ENISA). An early warning must be issued within 24 hours, the formal notification must follow within 72 hours, and a final report must be submitted within 14 days after the manufacturer has made available the security update addressing the vulnerability.

A reporting obligation also exists where the vulnerability is contained in a component (software library) provided by a third-party manufacturer and integrated into the product. In such cases, the decisive factor is merely whether the vulnerability in that component has been exploited, even if this occurred in a product of another manufacturer. As a result, many manufacturers may be required to report the same actively exploited vulnerability.

Where a manufacturer becomes aware of an actively exploited vulnerability, it must not only notify the relevant authorities but also inform users of the software without undue delay. This is intended to enable users to take appropriate countermeasures as quickly as possible.

Even where a vulnerability is not yet being actively exploited, the manufacturer may nevertheless be subject to a reporting obligation. This is the case where the vulnerability is contained in a component, as the manufacturer of that component must then be informed and must also be provided with information regarding the remediation of the vulnerability.

Reporting obligations in the event of security incidents

As with actively exploited vulnerabilities, manufacturers are also required to notify the relevant authorities and inform users where serious security incidents occur that affect the security of the software. In practice, this reporting obligation will be particularly relevant where the systems on which the software is developed have been compromised.

All reporting obligations under the Cyber Resilience Act apply in addition to the existing notification requirements relating to personal data breaches under the GDPR and incidents affecting critical infrastructure under the national transpositions of the Network and Information Systems Directive (NIS2).

New obligations regarding software security from December 2027

The reporting obligations are, however, only a small part of the regulatory burdens imposed on companies by the Cyber Resilience Act. Beginning on 11 December 2027, manufacturers of software and other products with digital elements will be required to comply with detailed technical security requirements for their products and will only be permitted to place such products on the market if they guarantee compliance with all applicable requirements by affixing a CE marking.

New obligations to provide security updates

Also from 11 December 2027, manufacturers will be required to comply with numerous obligations concerning the handling of vulnerabilities. Most notably, they must provide security updates free of charge for a support period of at least five years from the date the product is first made available. The obligation to provide security updates may only be waived where users are offered a free upgrade to the latest version of the product.

Risk of significant fines and collective actions

Violations of the Cyber Resilience Act may result in fines of up to EUR 15 million or 2.5% of the global annual turnover, whichever is higher. In addition, the Cyber Resilience Act provides for its enforcement through collective actions. Consumer protection organizations will therefore be able to seek injunctive relief through representative lawsuits.

Conclusion

Software vulnerabilities constitute a significant source of risk in our increasingly digitalized and automated society. The EU Cyber Resilience Act introduces a stringent new regulatory framework that companies must comply with in order to avoid substantial fines and the risk of collective litigation.

Author

Dr. Lukas Feiler, SSCP, CIPP/E, heads the Firm’s Commercial, Data, IPTech and Trade practice in Vienna. He is specialized in technology litigations, focusing on regulatory and civil disputes in the areas of data protection, AI, and platform regulation. Building on his litigation expertise, Lukas advises clients on strategic compliance issues in the areas of cyber security, data protection, and AI. Lukas also leads the AI Desk in Vienna and is a member of the Firm’s EMEA Data Privacy & Security leadership team. Lukas regularly represents clients before the Austrian Supreme Court, the Austrian Administrative Supreme Court, the European Commission, and the EU’s General Court and the CJEU.

Author

Silvia Grohmann, CIPP/E is an associate at the Vienna office of Baker McKenzie. The landscape of EU legislation in the technology law sector is one of her areas of expertise. Her practice has a particular focus on providing strategic advisory in the areas data protection law, cybersecurity and AI. Silvia is well known to consistently publish articles on current legal issues related to emerging technologies and has made a name for herself amongst the industry with her strategic analyses and practical advice.

Author

Nikolaus Schuberth is a junior associate of Baker McKenzie's IPTech Team in Vienna.