EU Cyber Resilience Act: Manufacturers face 24-hour deadline to report actively exploited vulnerabilities
yeswehack.com | blog | #bug-bounty | #compliance | #vulnerability-disclosure | #regulation | #product-security | #eu-cyber-resilience-act
Summary
The EU CRA's vulnerability reporting rules took effect on 11 Sept 2026: makers of digital products must report actively exploited vulnerabilities within 24h, facing fines up to EUR 15M.
- Published
- Collected
Skip to content