SQUAWK/NEWS
Account
Theme
Account
Menu
Live News REGULATION ARTICLE M impact

EU Cyber Resilience Act starts 24-hour vulnerability reporting clock

EU’s Cyber Resilience Act brings 24-hour vulnerability reporting into force, shortening the timeline for early warnings after exploited vulnerabilities are discovered.

One of the more practical provisions of Europe’s Cyber Resilience Act is starting to matter for software companies, as the window for reporting exploited vulnerabilities is getting much shorter. The EU framework requires manufacturers of products with digital elements to issue an early warning after becoming aware of an actively exploited vulnerability.