EU's Cyber Resilience Act starts the 24-hour vulnerability clock

https://image.theregister.com/224872.jpg?imageId=224872&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform

Manufacturers selling products with digital elements in the EU must now report actively exploited vulnerabilities to cybersecurity authorities under the Cyber Resilience Act's mandatory reporting rules.

The reporting duties set out in Article 14 of the CRA became applicable today. Subject to the regulation's exemptions, they apply to manufacturers of products with digital elements made available in the EU, regardless of where those manufacturers are based.

Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours.

The same deadlines apply to severe incidents affecting the security of products with digital elements.

The only difference in timing is related to the final report. Manufacturers must provide a final report on an actively exploited vulnerability within 14 days of making...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE