Development, begins together.
Banner alanı
IFM Sensor

🚨 Cybersecurity Alert: Machine Manufacturers Beware of CRA Reporting Period! 🚨

Mucitler Elektrik

Corporate
  • Mucitler
  • art_466_106c9eb6ff5408b65894a0a06d3b2b97.jpg

    Mitsubishi Electric is warning machine manufacturers about the upcoming vulnerability reporting deadline under the European Union's (EU) Cyber Resilience Act (CRA). This law introduces mandatory cybersecurity requirements for products with digital elements.

    🗓️ Upcoming Deadline: September 11, 2026​


    While the main obligations of the CRA will come into effect on December 11, 2027, the deadline for reporting actively exploited vulnerabilities and serious incidents has been set as September 11, 2026. From this date, machine manufacturers will be required to report to the European Union Agency for Cybersecurity (ENISA) and relevant cybersecurity incident response teams within 24 hours, 72 hours, and 14 days.

    ⚠️ Why Act Now?​


    Frederik Kok, Senior Cybersecurity Specialist at Mitsubishi Electric Europe, states that many companies will need to build their reporting capabilities from scratch. Kok emphasizes the importance of acting quickly to ensure compliance and avoid severe penalties, which can amount to up to 15 million Euros or 2.5% of their global annual turnover.

    🔍 ENISA and Mitsubishi Electric Support​


    • Machine manufacturers are advised to visit the ENISA website, which includes frequently asked questions about reporting obligations and the Single Reporting Platform (SRP).
    • As a CVE Numbering Authority (CNA), Mitsubishi Electric is authorized to assign CVE identifiers to vulnerabilities in its own products and publish vulnerability information in a standardized format. This experience enables them to support machine manufacturers in fulfilling their obligations under the CRA.

    Frederik Kok says, "I urge machine manufacturers to contact us immediately to comply with the vulnerability reporting deadline in September.
     
    Back
    Top