EU's Cyber Resilience Act starts the 24-hour vulnerability clock
Summary
The EU's Cyber Resilience Act has officially taken effect, introducing a mandatory 24-hour window for manufacturers to report actively exploited vulnerabilities and significant cybersecurity incidents. This new regulation requires companies to submit these reports to ENISA, the EU's cybersecurity agency, via a dedicated platform.
IFF Assessment
The Cyber Resilience Act mandates transparency and timely reporting of vulnerabilities and incidents, which benefits defenders by providing them with earlier awareness and opportunities to prepare.
Defender Context
This new EU regulation places a significant burden on manufacturers to disclose exploited vulnerabilities and critical incidents within 24 hours. Defenders should monitor ENISA's reporting platform for emerging threats and actively incorporate this new information into their threat intelligence and incident response planning.