EU Cyber Resilience Act enforces 24-hour vulnerability disclosure deadline

← Back to the feed

EU Cyber Resilience Act enforces 24-hour vulnerability disclosure deadline

The Register · 5 hours ago

The EU's Cyber Resilience Act has begun enforcing mandatory vulnerability and incident reporting, requiring manufacturers of products with digital elements sold in the bloc to alert authorities within tight deadlines when flaws are actively exploited. The rule, set out in Article 14, applies to any manufacturer making such products available in the EU regardless of where they are based, and marks another step in the bloc's phased rollout of stricter cybersecurity obligations.

Manufacturers must issue an early warning within 24 hours of becoming aware of an actively exploited vulnerability, a fuller notification within 72 hours, and a final report within 14 days of a fix becoming available; the same 24- and 72-hour deadlines apply to severe security incidents, with a final report due within a month. Reports must go through ENISA's new Single Reporting Platform to the relevant national CSIRT, and firms must also notify affected users without undue delay. These duties are classed as core obligations, meaning breaches could trigger the CRA's toughest fines of up to €15 million or 2.5% of annual turnover; most remaining CRA requirements, including security-by-design rules and mandatory software bills of materials, take effect from December 2027.

  • EU's Cyber Resilience Act reporting rules are now in force
  • Manufacturers must report exploited flaws within 24 hours
  • Non-compliance risks fines up to €15 million or 2.5% turnover

Art Celebrity Culture Cybersecurity Entertainment Technology

Read the full article at the source →

Originally published by The Register as “EU’s Cyber Resilience Act starts the 24-hour vulnerability clock”.