EU's Cyber Resilience Act starts the 24-hour vulnerability clock
Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform
Starting today, EU manufacturers of products with digital elements must report actively exploited vulnerabilities to cybersecurity authorities within 24 hours of discovering them, under the new Cyber Resilience Act (CRA). This reporting requirement, set out in Article 14 of the regulation, applies to manufacturers regardless of their location.
Within 72 hours of awareness, manufacturers must provide a more detailed notification. For severe incidents affecting product security, a final report must be submitted within 14 days of the implementation of corrective or mitigating measures. In more serious cases, the final report is due one month after the initial report. Darren Anstee, CTO for security at Netscout, emphasized that these reporting deadlines introduce a sense of urgency and prompt the timely gathering and release of critical information, enabling organizations to bolster their defenses and mitigate risks.
EU and non-EU manufacturers must submit reports through ENISA's Single Reporting Platform (SRP), addressed to the appropriate coordinating computer security incident response team (CSIRT). Manufacturers are also required to inform affected users about available corrections or mitigations without undue delay. Non-compliance with these reporting duties could result in significant fines, up to €15 million or 2.5 percent of the offender's annual turnover, whichever is higher.
The CRA is part of the EU's ongoing efforts to strengthen security regulations for companies operating within the bloc, with most remaining provisions set to take effect on December 11, 2027. Manufacturers will then be required to integrate security by design and default, eliminate default passwords, and ensure regular security updates.
Beyond enforcing faster responses to security flaws, the CRA aims to improve businesses' understanding of their software supply chains. Companies must maintain this security knowledge throughout a product's lifecycle by creating and updating a Software Bill of Materials (SBOM). This proactive approach is expected to reduce the frequency and impact of serious cyberattacks across the EU.
However, compliance teams should be aware of the CRA's overlapping requirements alongside other regulations like NIS2, DORA, the Data Act, and the AI Act, as this may prove challenging for organizations managing multiple digital initiatives concurrently.
Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.
- EU's Cyber Resilience Act starts the 24-hour vulnerability clock theregister.com