A major new cybersecurity regulation is about to hit software companies hard. The EU Cyber Resilience Act (CRA) — specifically its vulnerability reporting requirements — kicks in on September 11, and it's setting a deadline that leaves very little room for error: 24 hours to report any actively exploited security flaw to authorities.
Europe's New Cyber Law Gives Software Companies 24 Hours to Come Clean About Security Flaws
Starting September 11, the EU's Cyber Resilience Act forces software vendors to report actively exploited vulnerabilities within just 24 hours — and companies that don't know exactly what they shipped could be in serious trouble.
This is a Pro article
Subscribe to read the full article and support independent AI journalism.