SabiSys - Your Network Is Always On.
Support
Home Services
OverviewCloud & collaborationNetwork & WiFiHardwareInternet & fibreLandline & mobile telephonyMaintenanceBackup & continuity
Managed IT Cybersecurity Security check-up About Blog FAQ Contact Request your free audit
FREN
Security check-up · My IP · Speed test
+32 4 325 51 40 support@sabisys.be Office: Mon-Fri 9am-5pm · SLA clients: extended availability
← All articles Cybersecurity

Security flaws: since 11 September, manufacturers have to speak up

Since 11 September 2026, a European regulation has required manufacturers of hardware and software to report any actively exploited security flaw to the authorities within 24 hours. You do not build routers or software? This text still concerns you, for two very practical reasons: you will hear about problems affecting your equipment far sooner, and your purchasing criteria will have to change. Here is what matters, without the legal jargon.

What the regulation actually requires

The Cyber Resilience Act is the European regulation setting cybersecurity requirements for every product with digital elements. In practice: almost anything that connects or updates itself, from the firewall to the WiFi access point, from the IP camera to the backup NAS, from the network printer to your business application. It entered into force on 10 December 2024, and its first operational deadline fell on 11 September 2026.

Since that date, any manufacturer that discovers an actively exploited vulnerability in one of its products, or a severe incident affecting its security, has to report it to the authorities. The deadlines are tight: an early warning within 24 hours, a full notification within 72 hours, then a final report within 14 days for a vulnerability, once a fix is available. Reports go through the European platform run by ENISA and reach the relevant national centre, which in Belgium is the Centre for Cybersecurity Belgium. Next step: on 11 December 2027 the full set of obligations applies, with security by design, vulnerability handling across the product lifetime and CE marking.

Why it concerns you even if you build nothing

Until now, when a manufacturer found a flaw being exploited in the wild, it had no obligation to tell anyone. Some quietly shipped a patch, others waited. That era is over. In practice, you are going to see more security advisories, sooner, and more publicly.

That is excellent news, on one condition: that someone, in your company or at your provider, does something with them. A publicly disclosed flaw is also a flaw attackers know about. The dangerous window is no longer how long the manufacturer takes to react, but how long your company takes to apply the fix. In most SMEs we meet, the problem is not a lack of information: it is that nobody knows exactly what equipment is running, in which version, and since when.

The real issue: knowing what runs in your business

Try the exercise. How many devices in your company receive updates? Computers and servers, obviously. But also the router, the firewall, the WiFi access points, the backup NAS, the cameras, the printers, the alarm system, sometimes the time clock and the technical controllers. Each of those boxes runs firmware, and each one can become the way in.

This is exactly what we put in place for our contract clients: a living inventory of the estate, monitoring of installed versions and managed deployment of updates. Workstations and the Microsoft 365 side are handled through Intune, the network and the equipment through our managed services tooling. When an advisory comes out, the question is no longer "does this affect us?" but "here are the four devices concerned, when do we schedule it?".

The other classic blind spot is equipment the manufacturer no longer updates at all. It works, nobody complains, and it quietly accumulates flaws that will never be fixed. The new regulation will make those cases far more visible, because manufacturers will have to state how long a product will be supported.

What it changes when you buy

This is probably the most useful effect of the text for an SME. From December 2027, the support period will have to be stated clearly: how many years does the manufacturer commit to providing security fixes? That single figure changes how two quotes compare. A switch or a camera that is twenty per cent cheaper but supported for two years instead of seven is not a bargain.

You can already ask the question today, without waiting for the deadline. It is one of the reasons we work with professional ranges that have a documented lifecycle: Dell hardware for workstations and servers, UniFi equipment for network and WiFi. The purchase price is only part of the equation, the secured lifetime is another.

The one-sentence takeaway

Manufacturers now have to report exploited flaws within 24 hours: you will be warned sooner, so the only question that matters is knowing what equipment you have, in which version, and who applies the fixes.

Your action plan in 6 steps

  1. List everything that updates in the company: workstations, servers, firewall, access points, NAS, cameras, printers, alarm.
  2. Write down the installed version of each one, and the date of the last update applied.
  3. Spot the abandoned equipment, no longer supported by its manufacturer: those are your replacement priorities.
  4. Decide who applies the fixes and how quickly, then put it in writing. A critical patch should not wait for next month.
  5. Add the support period to your purchasing criteria, alongside price and performance.
  6. Check your backups while you are at it: they are what saves you when a fix arrives too late.

SabiSys handles the follow-up for you

Tracking the security advisories of ten different manufacturers is not an SME's job. It is ours. Under a managed services contract, we keep the inventory of your estate, follow your suppliers' publications and apply updates on a planned schedule, without interrupting your business. You get a clear status, not a pile of alerts.

Want to know where you stand? Our free security check-up tells you in three minutes, and a free, no-obligation audit reviews your whole setup, on site, in an hour. Get in touch with SabiSys, your IT partner in the Liège area.

Do you know what is running on your network?

Three minutes are enough to take stock.

Take the security check-up
Terms and conditions · SabiSys
Download the PDF

This site uses only technical cookies essential to its operation. No advertising cookies, no tracking.

FREN