EU Cyber Resilience Act mandates 24-hour vulnerability reporting
The EU Cyber Resilience Act, in force since Sept. 11, requires reporting actively exploited vulnerabilities and severe incidents within 24 hours. Experts say manual vulnerability triage is no longer viable, and the rules will affect hardware and GPU vendors worldwide.
- Exploited vulnerabilities must be reported within 24 hours
- Rules apply to non-EU firms, including GPU suppliers
- Reporting data is scattered across SIEM, SBOM and scanners
- Experts compare CRA's impact to the early days of GDPR
Read next
Policy