Urgent.News

What's breaking now, across thousands of outlets.

Tech

The EU Cyber Resilience Act's reporting clock starts September 11. What is your team actually doing about it?

September 11 is coming up fast, and I've had the same conversation with four different founders this month: " does the Cyber Resilience Act apply to us? " Every one of them assumed yes. Two of them were wrong. I run penetration testing and AI red teaming for SaaS companies at Faultline Security , so this is squarely in my lane, and I wanted to write the honest version of this instead of the…

The EU Cyber Resilience Act (CRA) is set to take effect on September 11, and companies are scrambling to understand its implications. Faultline Security, a company specializing in penetration testing and AI red teaming for SaaS firms, explains that the CRA's reporting obligations kick in once the 11th arrives. Companies manufacturing products with digital elements must actively report actively exploited vulnerabilities and severe security incidents through a single platform, with a 24-hour reporting window for early warnings and a 72-hour window for full notifications.

A final report must be submitted within a month (for vulnerabilities) or a year (for severe incidents). Fines for non-compliance can reach up to €15M or 2.5% of global turnover. However, the CRA's specific scope and reporting requirements remain unclear, particularly for SaaS companies. The article highlights that pure browser-delivered SaaS, which runs entirely in a browser tab, is generally not subject to the CRA.

However, any product that is installable, such as desktop or mobile apps, browser extensions, SDKs, CLI tools, or on-prem agents, falls under the CRA's purview. The article emphasizes the importance of understanding what constitutes an "actively exploited" vulnerability or security incident before it occurs, rather than reacting to incidents in real-time.

It argues that proactive vulnerability testing and internal tooling for the reporting process are crucial for compliance and avoiding costly fines.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Wednesday 26 August →