EU Cyber Resilience Act: Irish software firms face fines up to €15m
The EU Cyber Resilience Act's Article 14 reporting duties took effect on 11 September, requiring a 24-hour early warning and a 72-hour severity assessment for actively exploited vulnerabilities. Fines of up to 2.5% of global turnover or €15m begin in December 2027.
- 24-hour early warning and 72-hour severity assessment from the moment of awareness
- Final vulnerability report within 14 days of a fix; incident report within a month
- Fines reach 2.5% of global turnover or €15m, starting December 2027
- Scope covers apps, firmware and monetised freemium software
Read next
Policy