EU’s 24-Hour Cyber Rule: What It Means for Indian Auto Suppliers

New EU Cyber Resilience Act rules require digital mobility suppliers to log severe security incidents on ENISA platform within hours.

10 Sep 2026 | 1 Views | By Mukul Yudhveer Singh

Indian automotive suppliers selling connected products and software in Europe face a new cybersecurity clock from September 11, as reporting obligations under the European Union’s Cyber Resilience Act take effect.

For Indian Tier 1s, technology suppliers and automotive software companies doing business in Europe, the change is significant. It does not bring every automotive product under the CRA. But where a product with digital elements falls within its scope, discovering an actively exploited vulnerability or severe security incident can start a reporting clock measured in hours.

Manufacturers covered by the CRA will have to provide an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident. A more detailed notification follows within 72 hours. For an actively exploited vulnerability, the final report is due no later than 14 days after a corrective or mitigating measure becomes available. For severe incidents, the final report is required within one month of the 72-hour notification.

What Changes for Indian Suppliers?

The implications extend beyond companies headquartered in Europe. The CRA covers products with digital elements made available in the EU, which means an Indian headquarters does not by itself put a manufacturer outside the framework.

Automotive, however, has an important distinction. Vehicles and certain automotive products covered by the EU’s existing type-approval framework are excluded from the CRA. The new reporting regime should therefore not be interpreted as applying automatically to every ECU, component or system supplied for a European vehicle programme.

The picture changes for digital products outside that exclusion. Indian companies increasingly supply software, connected devices and other digital products around the vehicle and the wider mobility ecosystem. Where these fall within the CRA, suppliers will need to know whether a vulnerability is reportable and who takes responsibility once it is discovered.

That turns cybersecurity into more than an engineering issue. Developing and validating a fix may take time, but the initial reporting window is only 24 hours. For a Tier 1, the challenge is not just fixing a vulnerability. Information may have to move rapidly between engineering teams in India, cybersecurity functions, management, legal teams and European operations.

The Clock Starts Before the Wider CRA

The timing is important because most of the CRA’s broader requirements apply from December 11, 2027. The Article 14 reporting obligations, however, begin on September 11, 2026. Suppliers therefore cannot treat cybersecurity compliance solely as a preparation exercise for 2027.

The reporting requirements can also cover products within the CRA’s scope that were placed on the EU market before the wider requirements become applicable.

Notifications will be made through the Single Reporting Platform operated by the European Union Agency for Cybersecurity, ENISA. The platform becomes operational on September 11, creating a common route for manufacturers to make mandatory CRA notifications.

For companies operating across India and Europe, the immediate question is one of ownership. Someone has to identify a potentially reportable vulnerability, determine whether it meets the threshold and ensure the required notification is made. A 24-hour deadline leaves little room for uncertainty over who does what.

A Supply-Chain Question

The implications could run deeper for Tier 1 suppliers because automotive software rarely comes from a single source. Products can combine in-house software with code, libraries and components supplied by third parties or drawn from open-source projects.

An actively exploited vulnerability originating in a third-party component can still create reporting implications for a manufacturer whose product incorporates it. Knowing what sits inside a product, where vulnerabilities originate and which products could be affected therefore becomes increasingly important.

For Indian suppliers selling into Europe, that raises some uncomfortable but useful questions. Which products fall within the CRA? Who gets alerted when a vulnerability is discovered? Can an issue identified by an engineering team in India reach the right people quickly enough? And does the supplier have enough visibility into the software and third-party components inside its products to know where the risk lies?

From September 11, these are no longer questions for 2027. For Indian automotive suppliers connected to European supply chains, the first test of the CRA may not be how quickly they can fix a vulnerability, but how quickly they know they have one.

RELATED ARTICLES

Former PTI Associate Editor Rajkumar Leishemba joins Renault India

Kiran Murali 10 Sep 2026

The business journalist has moved to the automaker’s communications department.

Hero Motors Seeks to Widen Customer Base as Top 10 Clients Drive 73% of Revenue

Darshan Nakhwa 10 Sep 2026

The Auto component maker relies on new global programmes and complete powertrain systems to reduce exposure to its large...

Mahle Considers Non-Automotive Growth with Expansion into Rail Thermal Systems

Dev Vadchhedia 10 Sep 2026

Tier-1 supplier consolidates off-highway operations into dedicated division, showcasing locomotive cooling solutions at ...

NEXT STORY