Hello readers!
This week, we’re talking about the arrival of one of IoT’s biggest looming deadlines, the transformation of green energy, and more!
A single unpatched IoT device can now cost you millions

Reporting a security flaw in a connected product just stopped being a company's choice. On September 11, a new EU reporting obligation went live and turned vulnerability disclosure into a legal duty with a clock attached — and the rule doesn't only apply going forward. It reaches back: a router that shipped in 2019 and is still running in a warehouse or a hospital basement now falls under the same 24-hour disclosure clock as a product built to comply from day one. Nobody gets grandfathered in.
The mechanics explain why compliance teams spent the summer running tabletop drills. Under Article 14 of the Cyber Resilience Act, becoming aware of an actively exploited vulnerability starts a 24-hour clock for an early warning, a 72-hour window for a fuller notification, and a final report within 14 days of a fix. A TechTarget report on the deadline quotes Sai Honig, a senior advisor at cybersecurity consultancy Novera, making clear that continued exploitable risk, not the year a device shipped, decides whether it has to be reported. Fines for missing that window run as high as €15 million or 2.5 percent of a company's global annual turnover, whichever is larger — a number that turns disclosure from a courtesy into a budget line. ENISA's Single Reporting Platform went live the same day the obligation started, giving manufacturers no dry run before the clock began ticking on real incidents.
An importer, distributor, or service provider can inherit the same manufacturer duties if it puts its own brand on a device or meaningfully changes what that device does, according to guidance from Transforma Insights published on IoT For All — a detail that catches white-label hardware resellers and platform companies who assumed the rule was someone else's obligation. A certified modem or a hardened operating system inside the finished product doesn't transfer compliance either; the company that sells the whole device still owns the paperwork. None of this stays inside Europe's borders. The US, Japan, India, and Brazil are each drafting their own connected-device security rules using the EU's framework as a reference point, and a company still treating September 11 as a European problem is already miscalculating.
In 2020, the live question was still whether a company's own vulnerability disclosure policy could substitute for legislation, with op-eds at the time arguing that regulation alone wouldn't secure a market this fragmented. The Cyber Resilience Act settles that argument by making disclosure mandatory and pairing it with engineering requirements a voluntary policy never touched: a current software bill of materials covering every third-party component, an over-the-air update pipeline that can push a signed patch to a fleet without bricking devices in the field, and a default configuration that's already secure before a customer opens the box. Most industrial teams can say how many edge devices they run. Far fewer can say which software version sits on each one, and that visibility gap is what the engineering requirements are built to close.
The practical question for anyone building or buying connected products right now is whether the update and inventory infrastructure could produce a regulator-ready report inside 24 hours, regardless of whether a given device sells into the EU today — because the EU's baseline is what other regulators are copying, and today's export market is tomorrow's home market. Portainer's breakdown of the edge-fleet engineering requirements puts OTA infrastructure first for a reason: without a way to push a signed patch that fails safely instead of bricking a device mid-update, a company can identify a vulnerability and still miss the reporting deadline because it can't fix anything in time. Teams that built this infrastructure for their own reasons — faster patching, better fleet visibility — found September 11 was a formality. Everyone else just discovered how much technical debt now comes with a compliance deadline attached.
📖 Top Articles

The role of digital technologies in the energy sector continues to evolve as the adoption of new sustainable technologies increases. When Transforma Insights' Digital Transformation in Green Energy Tech report was first published in 2024, it highlighted the growing complexity of the energy system, including the integration of EVs, battery storage, smart meters, smart grids, microgrids, digital design and energy trading to support a more sustainable and decentralised energy system. Two years on, the 2026 report shows how these trends are accelerating and how the energy ecosystem is becoming even more interconnected, with the increasing adoption of technologies such as Virtual Power Plants (VPPs) adding further complexity.

Many commercial IoT projects begin with sensors, gateways, and cloud platforms. The interface comes later. By the time it does, the easiest option is often to place every available metric and control on a web dashboard.

Cameras can recognize people. Lights can follow schedules. Speakers can take voice commands. Storage systems can hold years of family photos and video. Yet the home as a whole often remains fragmented: security footage lives in one app, family files in another, automations somewhere else, and much of the intelligence still depends on separate cloud services. The problem is no longer a lack of smart devices. It is that data, computing, and control inside the home still operate in silos.
Amazon Developer Global Hackathon
Build and compete for $190K in prizes. The Amazon Developer Hackathon is an 8-week virtual challenge with multiple categories including smart home, wearables, voice AI, and building TV app experiences.
Create AI-enhanced experiences on Fire TV or extend Alexa+ with new agent capabilities. Integrate Bee wearable AI with any product or device or explore Amazon’s computer vision APIs to build IoT automation use cases and more.
You can build solo or join a team. The top prize is $40K ($25K cash + $15K AWS credits).
🔥 Rapid Fire
Factory AI hurdles: Data mapping, edge compute
UK-US supercomputers to build digital twins for fusion reactors
LTE dominates growing IoT module shipments
Z-Wave long range extends IoT reach beyond mesh networks
🎙 The IoT For All Podcast
In this episode of the IoT For All Podcast, Wienke Giezeman, CEO and co-founder of The Things Industries, joins Ryan Chacon to discuss how IoT is finally delivering what it promised ten years ago. The conversation covers what changed technically and commercially, the ROI of IoT, why deployments failed in the early days, criticism of IoT, what companies still get wrong about LoRaWAN, and The Things Conference 2026.
📆 Events & Webinars
Hosted by Informa Connect
The era of network convergence demands a unified response. Network X brings together operators, vendors, and innovators to navigate AI, cloud, and sovereignty complexity as one ecosystem.
15% Discount Code: IOTFORALL15
Brought to you by
Amazon Developer
Giving developers the tools to build awesome apps and games, and reach millions of consumers worldwide.






