Vendors now have 24 hours to report exploited flaws in the EU

Manufacturers selling software and connected products in the EU must report exploited flaws within 24 hours.

CSBadmin
2 Min Read

Manufacturers selling products with digital elements in the EU now face a 24-hour clock to report actively exploited vulnerabilities.

The reporting duties under Article 14 of the Cyber Resilience Act took effect today. They apply to makers of connected and software products made available in the bloc, no matter where the manufacturer is based, subject to the regulation’s exemptions.

Under the rules, a manufacturer must file an early warning within 24 hours of learning a vulnerability is being exploited. A fuller notification follows within 72 hours. The same deadlines cover severe incidents that affect a product’s security.

The obligation targets a long-standing blind spot. Vendors have often patched quietly, or not at all, leaving customers to run exposed gear with no way to judge their risk.

Security teams should expect a wave of vendor advisories as companies comply, and they should brace for faster vendor disclosures. If a researcher or attacker finds a flaw first, the 24 hours start once the maker becomes aware, not when the news breaks.

For defenders, the practical result is a shorter gap between a real-world exploit and official word from a supplier. Keeping an accurate inventory of products in scope, and a fast path from vendor notice to patched systems, matters more than ever.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.