CISOOnline

EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage

Independent security experts see the EU Cyber Resilience Act (CRA) reshaping international technology markets to emphasize cyber resilience from the ground up, thereby testing the operational capacities of technology vendors whose wares compete in those markets.

The EU CRA introduces mandatory reporting within 24 hours for any actively exploited vulnerabilities or severe incidents affecting products with digital elements. The reporting requirement, introduced Sept. 11, establishes an EU-wide product-security law for internet-connected hardware and software products that security experts see having broad implications beyond the EU.

Enterprise technologies such as security software, identity-management systems, operating systems, routers, firewalls, network management systems, VPNs, and more all fall within the scope of the regulation. The CRA establishes a legally binding EU regulation that applies even if a company is headquartered outside the EU.



Source link