Fast Check: How the EU Cyber Resilience Act Impacts Firewalls Following Recent Exploits

"Prevention is cheaper than a breach"

Following the CISA warning on July 3, 2026, regarding active exploits in Fortinet appliances, the intersection between US-based security alerts and the EU Cyber Resilience Act (CRA) has become a critical focal point for vendors and buyers. As attackers increasingly use AI-assisted fuzzing to accelerate vulnerability discovery, the CRA provides a clear framework for how such threats must be handled for devices sold within the EU.

Where Firewalls Sit Under the CRA

Under the CRA, products with digital elements are classified into specific tiers. Because FortiGate devices function as firewalls with intrusion detection and prevention systems (IDS/IPS), they are explicitly categorized under Annex III, Class II. This classification is significant because it disqualifies manufacturers from the ‘self-assessment’ route used for lower-risk products. Instead, under Article 32, manufacturers must utilize third-party conformity assessment routes, such as EU-type examination (Module B) or full quality assurance (Module H), involving a notified body.

The 24-Hour Reporting Clock

Starting September 11, 2026, the CRA mandates strict reporting obligations for actively exploited vulnerabilities. Once a manufacturer becomes aware of an exploit, they face a non-negotiable timeline:

  • 24 hours: Submit an early warning.
  • 72 hours: Submit a fuller notification.
  • 14 days: Submit a final report after corrective measures are available.

These requirements apply to both new and existing legacy products. While ENISA’s Single Reporting Platform is expected to be operational by the September deadline, the current lack of cited harmonized standards in the Official Journal means manufacturers must prepare for these rigorous requirements without the benefit of a established presumption of conformity.

Key Takeaways

For firewall vendors, the priority is to formalize internal triage processes to meet the 24/72/14-day reporting rhythm and secure third-party conformity assessments. For buyers, current vulnerability warnings serve as a benchmark for a vendor’s maturity. As the industry faces AI-accelerated threats, the CRA ensures that once the regulation is fully in force, manufacturers will be held to a transparent and unforgiving standard of cyber resilience.

Scroll to top