[{"data":1,"prerenderedAt":30},["ShallowReactive",2],{"nr-en-cyber-resilience-act-schwachstellen-meldepflicht-september":3},{"slug":4,"title":5,"dek":6,"date":7,"time":8,"publishedAt":9,"updated":10,"updatedAt":10,"dateFmt":11,"updatedFmt":10,"kind":12,"tier":13,"author":14,"authorName":15,"topics":16,"tracker":22,"trackerLabel":23,"headlineStat":24,"image":25,"ogImage":26,"imageAlt":5,"csv":10,"minutes":27,"words":28,"html":29},"cyber-resilience-act-schwachstellen-meldepflicht-september","Cyber Resilience Act: Manufacturers Must Report Vulnerabilities from September","The EU is tightening security requirements for product manufacturers. From September, a new obligation to report security vulnerabilities takes effect – alongside the AI Regulation and NIS2 Directive, German companies face complex compliance tasks.","2026-08-31","10:55","2026-08-31T10:55:00+02:00","","August 31, 2026","news","standard","ideal-syka","Ideal Syka",[17,18,19,20,21],"AI Regulation","Cyber Resilience Act","NIS2","Product Liability","Compliance","\u002Feu-digitalrecht-ticker","EU Digital Law","From September 2026: Obligation to report vulnerabilities","\u002Fnewsroom\u002Fimg\u002Fcyber-resilience-act-schwachstellen-meldepflicht-september.webp","\u002Fog-nr\u002Fcyber-resilience-act-schwachstellen-meldepflicht-september.en.png",3,589,"\u003Cp>The Cyber Resilience Act brings a new reality for European manufacturers: vulnerabilities must be reported from September onwards. This is just one of several regulatory waves hitting companies right now – and the requirements are piling up.\u003C\u002Fp>\n\u003Ch2>The essentials\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>From September 2026\u003C\u002Fstrong>, the obligation to report security vulnerabilities under the Cyber Resilience Act takes effect\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Since 02.08.2026\u003C\u002Fstrong>, transparency obligations under the AI Regulation (Article 50) are enforceable\u003C\u002Fli>\n\u003Cli>\u003Cstrong>From 09.12.2026\u003C\u002Fstrong>, the Product Liability Directive becomes relevant\u003C\u002Fli>\n\u003Cli>\u003Cstrong>NIS2 registration deadlines\u003C\u002Fstrong> have already passed (31.07.2026); fines up to \u003Cstrong>€10 million\u003C\u002Fstrong> or \u003Cstrong>2% of global annual turnover\u003C\u002Fstrong> threaten\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Transparency and liability: The regulatory triptych\u003C\u002Fh2>\n\u003Cp>The EU has created a globally recognized legal framework with the AI Regulation. Since early August 2026, transparency obligations under Article 50 have been enforceable – companies must document how their AI systems work. The company \u003Cstrong>VeroNex\u003C\u002Fstrong> has submitted the \u003Cstrong>EU2122\u003C\u002Fstrong> standard to the IETF to technically standardize AI verification evidence and ensure compliance with the EU AI Act and the Product Liability Directive.\u003C\u002Fp>\n\u003Cp>The Product Liability Directive follows from December 2026 – another milestone that holds manufacturers accountable. In parallel, courts are already dealing with concrete cases: the Munich Regional Court ruled in the GEMA v. Suno proceedings that training AI models is unlawful if it leads to memorization of protected content. The exception for text and data mining does not justify either the storage or the output of such content.\u003C\u002Fp>\n\u003Ch2>NIS2: Management liability and supply chain obligations\u003C\u002Fh2>\n\u003Cp>The NIS2 Implementation Act has been in force since 06.12.2025. Registration deadlines with the \u003Cstrong>Federal Office for Information Security (BSI)\u003C\u002Fstrong> have expired following a grace period until 31.07.2026 – and now it&#39;s getting serious for affected companies.\u003C\u002Fp>\n\u003Cdiv class=\"tbl-scroll\">\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Criterion\u003C\u002Fth>\n\u003Cth>Threshold\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Number of employees\u003C\u002Ftd>\n\u003Ctd>from 50 employees\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Turnover\u003C\u002Ftd>\n\u003Ctd>from €10 million\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Affected sectors\u003C\u002Ftd>\n\u003Ctd>18 defined industries\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Max. fine (particularly important entities)\u003C\u002Ftd>\n\u003Ctd>€10 million or 2% of global annual turnover\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Fine for late registration\u003C\u002Ftd>\n\u003Ctd>up to €500,000\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>A key aspect: \u003Cstrong>personal liability of management\u003C\u002Fstrong> and the passing of security requirements along the supply chain. Even companies not directly subject to the directive – such as car dealerships – are forced to comply with standards through contractual requirements from their clients. Typical requirements include multi-factor authentication (MFA), patch management, and incident management.\u003C\u002Fp>\n\u003Ch2>Legal analysis is in full swing\u003C\u002Fh2>\n\u003Cp>The complexity of the new regulations is evident in legal practice: the publisher \u003Cstrong>C.H. Beck\u003C\u002Fstrong> is publishing a comprehensive commentary on the AI Regulation at the end of August 2026 with 1,200 pages. At the same time, copyright issues are occupying courts – Carlsen Verlag has filed a lawsuit against OpenAI in connection with an AI-generated picture book. An expert, \u003Cstrong>Felix Stang\u003C\u002Fstrong>, pointed out that the probability of a purely coincidental match between the disputed picture book and the original is about 18,000 times lower than winning the lottery.\u003C\u002Fp>\n\u003Ch2>What this means for you\u003C\u002Fh2>\n\u003Cp>German companies are under pressure: regulation is no longer optional but concrete with specific deadlines. Those not yet registered risk substantial fines. The obligation to report vulnerabilities from September requires new processes – and the AI transparency obligations since August are already live. For many businesses, now is the time to bring legal and IT departments together and create a clear implementation plan. The question is no longer whether, but how quickly.\u003C\u002Fp>\n\u003Ch2>Sources\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fwww.ad-hoc-news.de\u002Fwirtschaft\u002Fcyber-resilience-act-hersteller-muessen-schwachstellen-ab-september\u002F70027665\">AD HOC NEWS\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cem>Editorially owned by \u003Ca href=\"\u002Fen\u002Fautor\u002Fideal-syka\">Ideal Syka\u003C\u002Fa>. Sources and method: \u003Ca href=\"\u002Fen\u002Fredaktion\">Newsroom &amp; method\u003C\u002Fa>. Tips and corrections: \u003Ca href=\"mailto:ai@i6eal.de\">ai@i6eal.de\u003C\u002Fa>.\u003C\u002Fem>\u003C\u002Fp>\n",1788173776319]