cybersecurity

US Cyber Information-Sharing Law Runs on Stopgaps While the EU Cyber Resilience Act Reporting Clock Starts

On 11 September 2026 a new obligation started for every company selling software or connected hardware in the EU. If a vulnerability in one of their products is being actively exploited, they now have 24 hours to send an early warning, 72 hours to file a notification, and 14 days after a fix is available to send a final report. It applies to products already on the market too. ENISA, the EU cybersecurity agency, opened its single reporting platform the same day.

Three weeks later, on 1 October, the final rule for America’s main incident-reporting law reached the White House budget office for review. It had been due a year earlier.

And the 2015 law that protects companies when they share threat data with the US government is now on its third short extension, due to expire again on 11 December.

Same problem, two very different speeds.

The European stack

The Cyber Resilience Act, Regulation (EU) 2024/2847, is a product law. It treats cybersecurity like electrical safety: if you sell it in Europe, it has to meet the rules for its whole supported life. Reporting started in September 2026. Full application, including design requirements, comes on 11 December 2027.

The other half is NIS2, the directive on the security of essential and important entities, from energy and transport to cloud providers and public administration. Member states had to transpose it by 17 October 2024. Most didn’t. The Commission sent formal notices to 23 of them in November 2024 and reasoned opinions to 19 in May 2025. By 1 January 2026, 20 of 27 had transposed.

On 9 July 2026 the Commission referred four countries to the Court of Justice and asked for fines: Ireland, Spain, France and the Netherlands. The Dutch adopted their law two days earlier, and it came into force in August. France and Spain still hadn’t adopted theirs by mid-2026.

So Europe’s rules are written, partly in force, and enforced unevenly. The gaps are in national capitals.

The American gaps

The US has taken a different route. It relies more on voluntary sharing and sector regulators, with one big mandatory reporting law on the way.

That law is CIRCIA, the Cyber Incident Reporting for Critical Infrastructure Act of March 2022. The proposed rule, published in April 2024, would require covered entities to report significant incidents within 72 hours and ransom payments within 24. Critics said it would cover about 300,000 entities across 16 critical-infrastructure sectors, far more than needed. The Cybersecurity and Infrastructure Security Agency missed the October 2025 statutory deadline, held town halls in June 2026 after a delay caused by the DHS funding lapse, and sent the final rule for review on 1 October 2026. The deadlines in it aren’t final until it’s published.

The information-sharing side is shakier. The Cybersecurity Information Sharing Act of 2015 gives companies liability protection when they share threat indicators with the government and each other. It lapsed on 30 September 2025, in the shutdown. The bill that ended the shutdown revived it to 30 January 2026. The full-year appropriations law extended it to 30 September 2026. The current stopgap carries it to 11 December 2026.

Ten-year reauthorisation bills exist in both chambers. They haven’t moved, partly because the chair of the Senate Homeland Security Committee, Rand Paul, has resisted clean extensions.

Why the difference matters

For a company operating in both markets, the comparison is awkward. The EU now tells it exactly when to report and to whom, with fines behind it. The US asks it to share voluntarily, under a legal shield that might expire in nine weeks.

Short extensions have a cost in themselves. Corporate lawyers advise on what’s protected. When the protection runs on two-month stopgaps tied to government funding fights, the safe advice is to share less.

Europe’s risk is the opposite one: a dense rulebook applied by 27 national authorities at different speeds. The CRA’s single reporting platform is an attempt to fix that by sending every report to ENISA and the national team at once. It’s the one piece of either system that got simpler this year.