Companies covered by the European Union’s Cyber Resilience Act, or CRA, must begin reporting actively exploited vulnerabilities and serious security incidents on 11 September.
The first warning must be submitted within 24 hours of a company becoming aware that a vulnerability is being actively exploited. A more detailed report must follow within 72 hours through the platform built for the CRA by the EU cybersecurity agency Enisa.
The requirements also apply to digital components sold separately on the EU market, including semiconductors and control circuits. Manufacturers based outside the EU are covered when their products are sold within the union.
The CRA will not apply in full until December 2027. Its reporting requirements, however, take effect on 11 September, creating an earlier compliance deadline for companies and manufacturers covered by the regulation.
Comments
0No comments yet. Be the first to comment.