Tech News
← Home  ·  All topics

Eu Cyber Resilience Act

3 GoKawiil briefs on this topic

EU's Cyber Resilience Act Sets 24-Hour Breach Reporting Rule

Beginning Friday, companies selling products in the EU must alert authorities within 24 hours of discovering serious security incidents affecting those products. The requirement is part of the Cyber Resilience Act, which imposes new cybersecurity obligations on manufacturers and vendors operating in the bloc.

EU Cyber Resilience Act's 24-hour breach reporting deadline arrives September 2026

An open-source maintainer describes receiving an extortion attempt disguised as a bulk vulnerability report—95 claimed flaws, only two or three real—followed by a $100,000 ransom demand threatening public disclosure. He argues this scenario foreshadows a legal reality coming for far more companies: starting September 11, 2026, the EU Cyber Resilience Act requires any manufacturer selling connected products into the EU to notify ENISA within 24 hours of learning that a vulnerability in their product is being actively exploited.

Study finds 76% of EU software vendors lack security.txt before CRA deadline

A scan of 623 European software vendor domains found that only 118 (24%) published a valid security.txt file with a working contact address, while 374 (76%) had none, according to a survey using RFC 9116 criteria. The check comes weeks before the EU Cyber Resilience Act's Article 14 takes effect, imposing a 24-hour reporting window once a vendor learns of an actively exploited vulnerability.