The EU Cyber Resilience Act’s vulnerability-reporting duties start September 11, forcing makers of connected devices and commercial software to report actively exploited flaws quickly. Product teams should treat the deadline as an operational change, not a paperwork exercise.