Skip to content

EU Launches 24-Hour Cyber Reporting Rule

EU Cyber Resilience Act Enforces Rapid Vulnerability Reporting

  • The EU Cyber Resilience Act now requires manufacturers to report actively exploited vulnerabilities within a strict 24-hour window.
  • Commercial crypto wallets are included under the Act’s definition of products with digital elements, imposing new security obligations.
  • The law distinguishes between commercial and non-commercial open-source software, impacting incident response strategies.

This regulatory change emphasizes the need for rapid incident response and reporting, affecting how companies handle vulnerabilities internally. The inclusion of crypto wallets under this framework highlights the growing integration of crypto security with broader software security measures.

Manufacturers must quickly assess and report vulnerabilities, shifting from traditional methods that waited for full technical investigations. This approach aims to enhance operational resilience across digital products in the European market. (Source)

Share