ReversingLabs, a software security firm, said in a blog post on 7 October 2026 that the EU Cyber Resilience Act's reporting rules have applied since 11 September 2026. Since then, makers must report flaws that attackers are actively using, and serious incidents, in products already sold in the EU. Older releases are included. The firm said the full rules start on 11 December 2027. It argues that checks will focus on the software as shipped, not on policies and questionnaires. As an example, it scanned a network appliance and found 12,263 components and 1,430 distinct known flaws. Nine of those flaws appear on CISA's list of exploited bugs.
ReversingLabs did not name the product or its maker, and says the numbers are real. The scan is the firm's own, and the firm sells binary analysis tools. It says such a scan cannot prove everything. It cannot show risk assessments, disclosure policies, or how the reporting process works. The post does not say whether the maker has seen the results.
Teams that sell software into the EU may need to back their claims with evidence from the final build, not only documents. ReversingLabs says companies that embed outside components become makers of their own products. It adds that a reportable flaw in one of those parts can trigger their own duty to report. It also says buyers can compare a supplier's parts list with one built from the shipped files.