AI Weekly Malaysia

Back to items Summaries

EU's Cyber Resilience Act starts the 24-hour vulnerability clock

ID
23538
Status
summarized
Published
11 Sep 2026, 7:34 PM
Fetched
11 Sep 2026, 11:31 PM
Provider
The Register
Category
technology
Original URL
https://www.theregister.com/security/2026/09/11/eus-cyber-resilience-act-starts-the-24-hour-vulnerability-clock/5295821
Source URL
https://www.theregister.com/headlines.atom

Summary

Score
6.5
Created
11 Sep 2026, 11:33 PM
Tags
Audience
developerssaas_founders

What happened

Article 14 of the EU's Cyber Resilience Act took effect on 11 Sep 2026, requiring manufacturers of products with digital elements sold in the EU to report actively exploited vulnerabilities within 24 hours via ENISA's Single Reporting Platform, with detailed notifications due in 72 hours and final reports within 14 days. The rules apply to non-EU manufacturers too, and require informing affected users of available corrections or mitigations.

Why it matters

If you ship any software, firmware, or connected hardware to EU customers—even from Malaysia—you now need a documented process to detect, triage, and report actively exploited vulnerabilities within 24 hours, or face non-compliance with the CRA. This means standing up incident-response runbooks and designating who files ENISA reports before a vulnerability forces an ad-hoc scramble.

Discussion angle

For founders and devs selling into the EU: do you have a 24-hour disclosure pipeline today, and what's the minimum viable incident-response process that satisfies CRA Article 14 without hiring a dedicated security team?

Top