The EU CRA’s early reporting mandate is now in effect, requiring manufacturers to report actively exploited vulnerabilities to ENISA and CSIRTs within 24 hours.
The European Commission’s cybersecurity package proposes amendments to NIS2 and a revised Cybersecurity Act. Here is what compliance teams need to track.