Last updated: 13 August 2026
From 11 September 2026, some developers making software available to users in the European Union must report actively exploited vulnerabilities and severe cybersecurity incidents.
These requirements form part of the European Union’s Cyber Resilience Act, Regulation (EU) 2024/2847.
Who is this information for?
This page is relevant to WPBay sellers who develop or distribute products containing functional software, including:
WordPress plugins, WordPress themes, extensions, scripts, applications and other software components.
The CRA may apply even when the seller or developer is located outside the European Union. A developer who markets software under their own name or brand may be considered the manufacturer of that software.
Using the GPL or another open-source licence does not automatically exempt a commercially distributed product. The CRA contains specific rules for free and open-source software, but software sold or otherwise monetised may still fall within its scope.
Whether the CRA applies depends on the product, how it is distributed and the seller’s individual circumstances. Each seller is responsible for determining and meeting the legal requirements applicable to their business and products.
What changes on 11 September 2026?
Article 14 of the CRA becomes applicable on 11 September 2026.
Manufacturers covered by the CRA must act when they become aware of either an actively exploited vulnerability or a severe incident affecting the security of a product with digital elements.
An actively exploited vulnerability is a vulnerability for which there is reliable evidence that a malicious actor has exploited it without the permission of the system owner.
A vulnerability does not become reportable merely because it has been discovered, publicly disclosed or assigned a CVE identifier. However, sellers should not wait for a CVE when reliable evidence of active exploitation already exists.
A severe incident is an incident that seriously affects, or is capable of seriously affecting, the security of the product. This may include compromising the availability, authenticity, integrity or confidentiality of important data or functions, or allowing malicious code to be introduced or executed in the product or a user’s systems.
Reporting through the EU Single Reporting Platform
Reportable events must be submitted through ENISA’s Cyber Resilience Act Single Reporting Platform.
| Stage | Deadline |
|---|---|
| Early warning | Without undue delay and no later than 24 hours after becoming aware |
| Vulnerability or incident notification | Without undue delay and no later than 72 hours after becoming aware |
| Final vulnerability report | No later than 14 days after a corrective or mitigating measure becomes available |
| Final severe incident report | Within one month after the 72-hour incident notification |
The reporting deadline begins when the manufacturer becomes aware of the active exploitation or severe incident. The initial report should not be delayed until the complete investigation or security update is finished.
The Single Reporting Platform is scheduled to become operational by 11 September 2026. An EU Login account will be required. ENISA currently advises manufacturers to begin platform registration and validation when they need to submit a notification.
The latest platform information is available on the ENISA Single Reporting Platform page.
Informing affected users
After becoming aware of an actively exploited vulnerability or severe incident, the manufacturer must inform affected users and, where appropriate, all users of the product.
The communication should clearly explain the affected product and versions, the potential impact, any security update that is available and any immediate steps users can take to reduce the risk.
Security communications should provide enough information for users to protect their websites without unnecessarily publishing technical details that could make exploitation easier.
Informing WPBay
If a reportable or potentially serious cybersecurity event affects a product listed on WPBay, contact support@wpbay.com as soon as possible.
Include the product name, affected versions, when you became aware of the event, the known or suspected impact, whether active exploitation has been confirmed, available mitigation steps and the expected availability of a security update. Please also provide proposed wording that WPBay may send to affected customers.
WPBay may help distribute security notices, contact customers, publish appropriate warnings or temporarily restrict a product’s availability while the risk is investigated or corrected.
Informing WPBay does not replace reporting through the EU Single Reporting Platform and does not transfer the seller’s legal obligations to WPBay.
Does this apply to existing products?
The reporting requirements can apply to products already made available on the European Union market. They are not limited to products first released after 11 September 2026.
Sellers should therefore maintain a way to receive, assess and respond to vulnerability reports for all supported products available through WPBay.
What happens in December 2027?
Most other CRA requirements become applicable on 11 December 2027.
Depending on the product and circumstances, these broader obligations may concern secure product development, cybersecurity risk assessments, vulnerability handling, security updates, technical documentation, declared support periods, conformity assessments, user information and CE marking.
WPBay will provide sellers with additional guidance as the implementation details and relevant standards develop.
Further information
Official information is available from:
Cyber Resilience Act reporting obligations — European Commission
Cyber Resilience Act legal text — EUR-Lex
Single Reporting Platform and FAQs — ENISA
Cyber Resilience Act and open-source software — European Commission
Important notice
This page provides general information and does not constitute legal advice. WPBay cannot determine whether the CRA applies to a particular seller or product. Sellers should obtain independent legal or cybersecurity advice where necessary and consult the latest official European Union guidance.
