EU cyber rule exposes gaps in product security operations | TechTarget
The EU's 24-hour vulnerability reporting clock is now running for manufacturers of connected hardware and software. Under the new reporting provisions, product-security teams must quickly determine whether a flaw is present in a shipped product and under active exploitation.
The reporting provisions of the EU's Cyber Resilience Act (CRA) took effect September 11. It requires manufacturers to submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident, followed by a fuller notification within 72 hours.
Final reports are due within 14 days after a corrective measure becomes available for a vulnerability or within one month of the 72-hour notification for a severe incident. The requirements cover products already on the EU market; most other CRA provisions take effect December 11, 2027.
The new European reporting rule could establish a global product-security standard, but it will be difficult for smaller manufacturers and...
Copyright of this story solely belongs to www.techtarget.com. To see the full text click HERE