EU Cyber Resilience Act Brings 24-Hour Vulnerability Reporting Into Force

1 hour ago 3



TL;DR Parts of the EU Cyber Resilience Act’s vulnerability-reporting regime are now applicable. Manufacturers must issue early warnings for actively exploited vulnerabilities within 24 hours. Commercial crypto wallets can fall within the broader category of products with digital elements. One of the more practical pieces of Europe’s Cyber Resilience Act is starting to matter for software companies: the clock on exploited vulnerabilities is getting much shorter. The EU framework requires manufacturers of products with digital elements to issue an early warning after becoming aware that a vulnerability is being actively exploited. The initial reporting window is 24 hours, with more detailed follow-up information required later. The rules sit inside the EU’s wider Cyber Resilience Act, which covers connected hardware and software products sold into the European market. Crypto Wallets Sit Inside A Much Bigger Rulebook This is not a crypto-specific law. That is worth making clear because the implications for wallets come from the way the CRA defines digital products rather than from a special section written specifically for crypto. Commercial hardware wallets and wallet software placed...

Read Entire Article