RM IT SecOps Daily
Enterprise Tech

First Cyber Resilience Act reporting deadlines start to bite for hardware vendors

Manufacturers must now disclose actively exploited vulnerabilities within 24 hours of becoming aware.

Grace Nwosu

Enterprise IT Correspondent 5 min read

Team reviewing documents in a dimly lit meeting room
Disclosure timing is now a board-level question. Photo: Unsplash

Legal teams and product security groups are discovering they disagree about what awareness means. This story is developing and will be updated as our newsroom confirms further detail with affected organisations and responders.

  • #Regulation
  • #CRA
  • #Disclosure