EU Cyber Resilience Act's 24-Hour Reporting Requirement Now Enforced for IoT Vendors
The EU CRA's vulnerability-reporting regime became active September 11, 2026, requiring IoT manufacturers to report exploited vulnerabilities within 24 hours or face penalties.
EU reporting obligations create immediate compliance costs
The EU Cyber Resilience Act now requires manufacturers of connected devices to report actively exploited vulnerabilities through the EU platform within 24 hours of discovery. The regulation became enforceable on September 11, 2026, affecting any vendor selling products with digital elements into Europe.
The reporting timeline is strict: 24 hours for an initial warning, 72 hours for a full vulnerability notification, 14 days after a patch is available for the final report on an exploited vulnerability, and one month after the 72-hour notification for serious incident reports. The CRA's broader product-security requirements become mandatory December 11, 2027, with transitional certification provisions starting June 11, 2028.
This changes procurement requirements. European enterprise buyers should add CRA-readiness to vendor questionnaires for any connected product. The key budget implications extend beyond license costs: buyers need funds for asset discovery, firmware provenance tracking, vulnerability monitoring, incident-response integration, and evidence retention. Vendors that already provide software bills of materials, vulnerability disclosure workflows, signed firmware updates, device inventories, and long-term patch support now hold a measurable compliance advantage.
The regulation increases pressure on device makers currently relying on general-purpose IT security tools rather than product-level security platforms. Embedded-security vendors such as Exein, operating-system providers such as Canonical, and IoT-management platforms offering fleet inventory and over-the-air updates compete directly on CRA-readiness.
Canonical extends Zephyr support to 15 years
Canonical announced Zephyr 26.04 LTS on September 21, offering up to 15 years of security maintenance for embedded and IoT deployments. The release extends beyond Zephyr's standard five-year upstream support period, targeting industrial controllers, gateways, medical devices, and other systems with decade-plus lifecycles.
The differentiator is support duration, not disclosed performance or per-device price. Zephyr competes with embedded Linux distributions, vendor-specific real-time operating systems, FreeRTOS, QNX, and Wind River VxWorks. Long support periods reduce the need for costly hardware refreshes, but the announcement omits pricing, support-tier costs, patch-service SLAs, and independent security benchmarks.
Enterprises should request the commercial support price, CVE response targets, supported chipsets, backport policy, and whether the 15-year period applies to every component or only defined portions of the platform. A vendor claim of extended support means little without contractual terms specifying patch latency, vulnerability-detection coverage, and device-fleet limits.
NTT DOCOMO BUSINESS plans security-integrated IoT network
NTT DOCOMO BUSINESS announced SIGN^® Pro, an IoT network service with built-in security features scheduled for March 2027. The service bundles connectivity, device management, and security into a single managed offering, reflecting a broader market shift away from buying these layers separately.
The model could appeal to enterprises lacking internal expertise in SIM/eSIM lifecycle management, network segmentation, and device security. However, the announcement provides no pricing, supported device counts, security-control specifications, or performance benchmarks.
Buyers should demand details on identity management, private networking, threat detection, firmware handling, logging, geographic coverage, outage SLAs, and integration with existing platforms from AWS, Microsoft, Google, or dedicated IoT-management vendors. "Built-in security" is a positioning claim, not evidence. The service will compete with managed IoT connectivity and security offerings from telecom operators, cellular IoT specialists, and cloud-connected device platforms.
Exein's $270 million round signals embedded-security consolidation
IoT-security company Exein raised $270 million in a funding round led by Headline at a $1.7 billion valuation, bringing total funding to more than $600 million. Exein began with an IoT-security focus and is expanding toward security for "physical AI"—connected devices and machines incorporating increasingly autonomous software.
The financing strengthens Exein against embedded-security and device-protection competitors including Armis, Forescout, Microsoft Defender for IoT, Nozomi Networks, and Claroty. The competitive boundary is becoming less clear: traditional IoT-security platforms emphasize fleet visibility and network behavior, while embedded-security vendors emphasize protection inside the device, firmware, and software supply chain.
The valuation and funding size signal market confidence, not product superiority. Enterprise buyers should evaluate Exein against alternatives using measurable criteria: percentage of device types supported, firmware-analysis coverage, false-positive rates, deployment overhead, SBOM and vulnerability-detection accuracy, remediation workflow, and pricing per device or per fleet. The announcement supplies no customer count, benchmark results, or pricing, so it is more significant as a financing and competitive-positioning event than as evidence of immediate operational advantage.
What to do now
Treat CRA reporting capability as a procurement requirement for products sold or deployed in Europe. Require vendors to state security-support duration in contracts; Canonical's 15-year Zephyr claim illustrates the importance of lifecycle terms. Separate network-security claims from device-security evidence—a managed IoT network does not automatically establish firmware integrity, vulnerability remediation, or device identity.
Demand comparable metrics from vendors: supported device models, patch latency, vulnerability-detection coverage, false-positive rates, device-fleet limits, and total cost per device. Expect greater competition between embedded-security specialists, operating-system providers, and managed-connectivity vendors as CRA compliance becomes a measurable differentiator rather than a marketing claim.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
