EU Cyber Resilience Act: 24-Hour Vulnerability Reporting Now Mandatory
11 Articles
11 Articles
EU Cyber Resilience Act: 24-Hour Vulnerability Reporting Now Mandatory
The EU's Cyber Resilience Act has entered enforcement, requiring manufacturers to report actively exploited vulnerabilities in their products within 24 hours. The rules impose steep fines for noncompliance and aim to accelerate defender response across hardware, software, and connected systems. This marks one of the strictest mandatory disclosure timelines globally.
Cyber Resilience Act: From September 11th, the 24-hour reporting obligation applies to security vulnerabilities and incidents. Many companies are not yet prepared
Finite State highlights firmware visibility challenge as EU Cyber Resilience Act vulnerability reporting begins
Finite State, vendor of product security and software supply-chain risk management, announced that connected device manufacturers using its platform are ready for the EU Cyber Resilience Act’s Sept. 11 reporting obligations. These manufacturers will enter the deadline able to answer the notification’s hardest question: whether an actively exploited vulnerability is present and reachable in the
As of today, those who sell hardware or software with digital connectivity in the European market have 24 hours to confess their own security problems. The reporting obligation under the Cyber Resilience Act EU has been triggered, the legislation requiring manufacturers to disclose actively exploited vulnerabilities and serious incidents through the new platform [...]
The new reporting obligation under the EU's Cyber Resilience Act came into effect today. Manufacturers must report actively exploited vulnerabilities within 24 hours; breaches could result in fines of up to €15 million.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium



