Europe Started Policing Device Security on 11 September 2026 - And Your Travel Router Is In Scope
The EU Cyber Resilience Act reporting obligations went live on 11 September 2026, covering phones, laptops, smartwatches, routers and travel hotspots. Manufacturers must now report actively exploited vulnerabilities on a deadline - including for devices already sold.
A European law that most travelers have never heard of started to bite on 11 September 2026, and it applies to almost every piece of hardware in a carry-on bag: phones, laptops, smartwatches, routers and the pocket-sized travel hotspots that have quietly become standard kit.
The law is the EU Cyber Resilience Act (CRA). Most of it does not take full effect until 11 December 2027. But one part β the reporting obligations in Article 14 β has been live since 11 September 2026, and it is the part that changes what happens after something goes wrong with a device you already own.
What actually changed on 11 September
Under Article 14, a manufacturer of a product with digital elements must report to European authorities when it becomes aware of either an actively exploited vulnerability in its product, or a severe security incident affecting it. The clock is strict: a final report is due no later than 14 days after a fix or mitigation is available for an actively exploited vulnerability, and within one month for a severe incident.
The scope is deliberately broad. It covers software applications, IoT products, routers, connected machinery and separately marketed digital components β in practice, smartphones, laptops, smart home products, smartwatches, connected toys, microprocessors and firewalls.
Two details matter for consumers. First, it also applies to products already on the EU market, not just new models, so a router you bought two years ago is not outside the regime. Second, the obligation is not retroactive: a manufacturer does not have to report something it already knew about before 11 September 2026, but everything it learns from that date forward is in scope.
Why a connectivity site is writing about a compliance deadline
Because the devices that keep you online abroad are exactly the category that has historically been worst at this.
Your phone is fine. Apple, Google and Samsung run mature security programmes, publish advisories and ship patches for years. The problem has always been everything else in the bag: the β¬25 travel router bought from a marketplace listing, the portable hotspot from a brand with no support page, the eSIM-capable gadget whose firmware was last updated the month it shipped. Those products sit directly in your traffic path β every request from your laptop and phone goes through them β and until now, nothing obliged the vendor to tell anyone when one of them was being actively exploited.
Travel hardware has been moving in this direction for a while. eSIM is leaving the phone: 5G dongles, travel routers and tablets now ship with an eSIM already loaded, which means more devices in the bag that hold connectivity credentials and need firmware maintenance. A reporting regime that forces manufacturers to surface active exploitation, on a deadline, is the first real pressure on the cheapest end of that market.
It is worth being precise about what the CRA does and does not do. It does not scan your device. It does not guarantee patches reach you. It creates an obligation to report to authorities, which over time forces vendors to build the vulnerability-handling processes they should already have had β and makes the ones that cannot do it visible.
What this means on your next trip
Nothing about this changes how you pack, but it does change what is reasonable to expect from a vendor:
- Prefer devices from a manufacturer with a support page. After September 2026, a company selling into the EU with no vulnerability-handling process is a company with a compliance problem. That is now a signal you can read.
- Update firmware before departure, not during. Travel routers and hotspots almost never auto-update. Patching at home on a trusted connection is the single highest-value thing you can do.
- Fewer devices in the path is safer. Every travel router is one more thing carrying your traffic and holding credentials. If your phone can act as the hotspot, the extra hardware may not be earning its place.
- Keep connectivity on the phone when you can. A travel eSIM such as HOLASIM installs directly onto the handset β the device in your bag with the longest patch support and the best security track record β instead of adding another box to maintain.
- Check whether the device holds an eSIM profile. If a router or tablet carries its own eSIM, treat it like a phone: same update discipline, same care about who made it.
The broader arc is that connected hardware is being pulled into the kind of accountability software has had for years. For travelers, the practical read is simpler than the regulation: the number of devices carrying your data abroad has quietly grown, and the cheapest ones have been the least maintained. A reporting deadline in Brussels does not fix that by itself, but it is the first time anyone has been legally obliged to say something is broken.
Related: eSIM beyond phones: laptops, tablets and travel routers and eSIM scams in 2026: five traps travelers keep falling for.