Cyber Resilience Act reporting rules kick in – Are you CRA compliant?

The EU’s Cyber Resilience Act (CRA) reaches a critical milestone tomorrow (11 September) as its incident reporting obligations officially take effect. Under the new framework, manufacturers, distributors and importers of digital products, including software products, must submit a warning within 24 hours of becoming aware of an actively exploited vulnerability or security incident. The Act applies to vendors within and also selling into the EU.

To support these requirements, the EU’s cybersecurity agency, ENISA, is launching a dedicated single reporting platform – though its research suggests a gap between awareness and practical readiness. While 66% of organisations surveyed were aware of the CRA, there is still room for improvement, especially within smaller organisations.

For products in scope, manufacturers must report an exploited vulnerability or security incident within 24 hours of becoming aware of it, with a fuller notification within 72 hours. Manufacturers need to be clear which products fall within the CRA and, also, that their incident response processes are capable of identifying and reporting within 24 hours.

Darren Anstee, CTO for security at NETSCOUT, said: “These reporting obligations, and the availability of the Single Reporting Platform, mark a shift in how digital product manufacturers must report on exploited vulnerabilities and security incidents affecting their products. Having a single place to report, which will then automatically propagate information across the region, will help to ensure relevant information is quickly disseminated.

“The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt. Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk.”

Here’s some helpful links for reference:

https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

https://www.enisa.europa.eu/topics/product-security/single-reporting-platform-srp

https://www.enisa.europa.eu/news/where-do-smes-stand-in-preparing-for-the-cyber-resilience-act

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top