
EU Cyber Resilience Act reporting rules go live: Hardware and software vendors face mandatory 24-hour disclosures
The EU CRA’s early reporting mandate is now in effect, requiring manufacturers to report actively exploited vulnerabilities to ENISA and CSIRTs within 24 hours.
Tom Verhoeven











