The EU Cyber Resilience Act now requires vulnerability reports within 24 hours.

Read the latest update on how the EU Cyber Resilience Act now requires vulnerability reporting within 24 hours.

Frequently Asked Questions
FAQs The EU Cyber Resilience Acts 24Hour Vulnerability Reporting Rule

Basics

What is the EU Cyber Resilience Act
Its an EU law that sets cybersecurity requirements for products with digital elementslike software smart devices and connected hardwaresold in the EU

Whats this 24hour vulnerability reporting rule
If a product has a actively exploited vulnerability the manufacturer must report it to the relevant EU authority within 24 hours of becoming aware of it

Who has to report
Manufacturers and vendors who place products with digital elements on the EU market Importers and distributors also have obligations to pass information along

When does this take effect
The Cyber Resilience Act entered into force in December 2024 The main obligations including reporting apply from December 2027 with some reporting duties starting earlier under related rules

Does this apply to companies outside the EU
Yes If you sell products with digital elements in the EU the rules apply to you regardless of where your company is based

Definitions Scope

What counts as an actively exploited vulnerability
A flaw that attackers are actually using in the wild right nownot just a theoretical risk or a proofofconcept

What counts as a product with digital elements
Basically any hardware or software with network connectivity or digital functionalitylaptops routers apps IoT devices operating systems and more There are some exceptions like certain medical devices and cars covered by other rules

What exactly do I have to report in those 24 hours
An early warning that an actively exploited vulnerability exists and basic details A fuller report follows within 72 hours and a final report within 14 days

Who do I report to
Your designated EU member state authoritytypically your national cybersecurity agency or a CSIRT

Benefits Purpose

Why only 24 hours
Fast reporting lets authorities warn other potential victims and coordinate a response before the damage spreads

Whats the point of reporting so early before Ive fixed it
Early warnings help others defend themselveslike patching blocking or monitoringwhile you work on a fix

Does this make products safer for consumers
Yes It forces faster transparency and quicker responses to real threats which benefits everyone using the product

Scroll to Top