www.industryemea.com

Machine builders must act now to meet CRA vulnerability reporting deadline, Mitsubishi Electric warns

Ratingen, Germany – August 24th, 2026 Mitsubishi Electric Europe B.V. is urging machine builders to act now to ensure that they are ready for the Cyber Resilience Act’s (CRA) upcoming vulnerability reporting deadline.

  emea.mitsubishielectric.com
Machine builders must act now to meet CRA vulnerability reporting deadline, Mitsubishi Electric warns

Frederik Kok, Senior Cyber Security Expert, Mitsubishi Electric Europe

First introduced by the European Union (EU) on 10 December 2024, the CRA establishes mandatory cybersecurity requirements that manufacturers and retailers must incorporate into the planning, design, development and maintenance of products with a digital element to continue selling them in EU markets.

While the main obligations of the Act are not due to apply until 11 December 2027, the deadline for the mandatory obligation to report actively exploited vulnerabilities and severe incidents is fast approaching on 11 September 2026. From this date, machine builders must follow a strict, three-tiered reporting deadline with the European Union Agency for Cybersecurity (ENISA) and relevant cyber security incident response teams, with specific actions to be taken with 24 hours, 72 hours, and 14 days of an incident.

In light of this, Frederik Kok, Senior Cyber Security Expert at Mitsubishi Electric Europe B.V., is calling on machine builders to take swift action to ensure that they are ready for the mandatory September deadline.

“While machine builders who are already compliant with the EU’s NIS2 Directive will be in a strong position to meet the CRA’s vulnerability reporting requirements, many more besides will need to build the necessary reporting capabilities from the ground up,” he explains.

“It’s understandable why the upcoming deadline may seem like a daunting prospect for these organisations, and we recognise that navigating the various requirements might be a difficult task. As such, we stand ready to support machine builders in ensuring compliance and avoiding severe penalties, which could equate to up to €15 million, or 2.5% of their global annual turnover, depending on which is higher.

Machine builders are advised to visit the website of the European Union Agency for Cybersecurity (ENISA), which is responsible for establishing and operating the CRA Single Reporting Platform (SRP). ENISA has also launched a webpage with frequently asked questions on reporting obligations and the development of the Single Reporting Platform: Single Reporting Platform (SRP) | ENISA

Furthermore, as a CVE Numbering Authority (CNA), Mitsubishi Electric is authorised within the global CVE programme to assign CVE identifiers to vulnerabilities affecting products within its scope, and to publish vulnerability information in a standardised, internationally recognised format.

“Mitsubishi’s status as a CNA embodies our practical experience in vulnerability management, and means that we are well placed to support machine builders in meeting their obligations under the CRA,” Frederik continues.

“With a little over a month to go, I would urge machine builders to get in touch with us now to avoid falling afoul of September’s vulnerability reporting deadline.”

For more information, please visit: https://emea-fa.mitsubishielectric.com/fa/service/cyber_security/cyber-resilience-act

  Ask For More Information…

LinkedIn
Pinterest

Join the 155,000+ IMP followers