EU Cyber Deadline Raises Reporting Stakes for UK Gambling Technology
UK gambling firms placing digital products on the EU market may face strict cyber reporting deadlines from 11 September 2026.
UK gambling operators and suppliers placing digital products on the European Union market may face new cyber incident reporting duties from 11 September 2026. The European Union’s Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities and severe incidents involving products with digital elements.
The deadline does not create a new Great Britain licence condition. It applies under European Union law. However, it can affect businesses based in the United Kingdom when they place covered products on the European Union market.
What changes on 11 September
The European Commission says manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe incident. A fuller notification must follow within 72 hours.
Final reports are due within 14 days after a corrective measure becomes available for an exploited vulnerability. For a severe incident, the final report is due within one month.
Reports will be submitted through the Cyber Resilience Act Single Reporting Platform. Notifications go to the relevant Computer Security Incident Response Team and are made available to the European Union Agency for Cybersecurity, known as ENISA, unless exceptional circumstances justify a delay. The platform is scheduled to become operational on 11 September 2026.
The practical change is a separate European Union reporting track with deadlines measured in hours, not just the existing Great Britain compliance process.
Why gambling technology may be covered
A legal analysis published by DLA Piper on 18 August 2026 says the rules may cover downloadable casino and sportsbook clients, mobile gambling applications, gaming cabinets, self-service betting terminals, kiosks and player-account management platforms.
The analysis also identifies a potential risk for operators that heavily customise supplier technology. An operator that distributes an application under its own brand or substantially modifies a product may assume manufacturer responsibilities under the Act.
- Mobile casino and sportsbook applications may fall within the product rules.
- Self-service betting terminals and kiosks may be covered.
- Player-account platforms may require a formal assessment of responsibility.
- Customised supplier systems may create additional duties for the operator.
Separate duties in Great Britain
Gambling businesses serving consumers in England, Scotland and Wales must still meet the Gambling Commission’s licensing framework. Its remote gambling and software technical standards apply to licensed remote operators and gambling software providers.
The Commission also requires covered remote gambling operators to complete an annual independent security audit. Major non-conformities identified in an audit must be reported to the Commission without delay.
These Great Britain requirements operate separately from the European Union reporting deadline. They arise under the Gambling Act 2005 and the Gambling Commission’s licence framework.
The distinction matters for companies operating across several markets. Compliance with Great Britain’s technical standards will not, by itself, establish compliance with the Cyber Resilience Act.
What businesses need to clarify
Before 11 September, affected businesses need to establish who controls cyber decisions, which products are placed on the European Union market and which incident response team owns each notification.
They also need clear records covering:
- vulnerability detection and triage;
- incident escalation and decision-making;
- supplier and platform responsibilities;
- customer warnings and corrective measures;
- the time when the business became aware of an incident.
For UK-facing gambling technology, the main challenge is running both systems without confusing an European Union market access obligation with a Gambling Commission licence requirement. A supplier may need separate procedures for identifying the legal manufacturer, assessing market placement, escalating incidents and meeting the 24-hour and 72-hour reporting windows.