Policy/ cyber resilience act · eu regulation · vulnerability disclosure · supply chain security

EU Cyber Law Gives Firms 24 Hours to Report Active Hacks

A new EU deadline forces makers of connected products to report actively exploited flaws within 24 hours, starting September 11.

The EU's Cyber Resilience Act starts the clock on hack disclosures next week.

Under the Cyber Resilience Act, manufacturers selling products with digital elements in the European Union must notify regulators within 24 hours of learning that a vulnerability in their product is being actively exploited. A more detailed follow-up report is due within 72 hours. The rule takes effect September 11. It applies broadly to anything with a digital element sold in the EU, not just traditional software vendors.

This kind of speed requirement forces companies to build real detection and reporting pipelines instead of quietly patching and hoping nobody notices. It also gives regulators, and by extension the public, a much earlier signal when something in the software supply chain is under active attack, rather than finding out months later in a breach disclosure.

Whether a 24-hour clock actually improves security or just produces a flood of rushed, incomplete filings is the open question - breach-notification deadlines in other sectors have generated plenty of both.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →