From 11 September 2026
Reporting
Manufacturers must report both actively exploited vulnerabilities and severe incidents. A vulnerability counts as actively exploited when there is reliable evidence that a malicious actor has used it. A severe incident is anything that harms, or has the potential to harm, your product's ability to protect the availability, authenticity, integrity, or confidentiality of important data or functions. Once you become aware of either, the clock starts: an early warning within 24 hours, a full notification within 72 hours, and a final report – 14 days after a fix or mitigation is available for a vulnerability, one month after the 72-hour notification for a severe incident.
Reports go through ENISA's Single Reporting Platform to the national CSIRT where your main EU establishment sits, and to ENISA. Affected users must be informed without undue delay.
Reporting obligations apply to products already on the EU market, not only new ones.
From 11 December 2027
Fixing without delay
The remaining requirements take effect, including conformity assessment and CE marking. Manufacturers must handle vulnerabilities throughout the support period and remediate them without delay, including through security updates.
That is the standard AISLE helps manufacturers meet: find, fix, and verify, continuously.