Threat Intelligence

EU's New Cyber Resilience Act Sets 24-Hour Breach Reporting Deadline

Dark Reading · 10 Sept 2026
Key Takeaway If your business sells products or services connected to the EU, review your incident detection and reporting processes now to ensure you can meet a 24-hour notification deadline.

A significant new regulatory requirement is taking effect for businesses operating in the European Union. Under the EU Cyber Resilience Act, companies must notify government authorities within just 24 hours of discovering a serious security incident affecting their products.

This tight reporting window represents a major shift in how quickly organisations are expected to detect, assess, and act on security issues. For businesses that sell products or services into EU markets, even those based in Australia, this could mean reviewing internal incident response processes to ensure they can meet such a short deadline.

While the rule directly applies to EU operations, Australian small businesses with European customers, partners, or supply chain links should pay close attention, as compliance obligations can flow through international business relationships.

EU Cyber Resilience Act incident reporting compliance regulation supply chain
Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.