New EU Rule: Cyberattacks Must Be Reported Within 24 Hours
6 Articles
6 Articles
The Cyber Resilience Regulation requires a notification to the European Cybersecurity Agency and the relevant national emergency team, then a report within 72 hours and later a final report. The article Actively exploited vulnerabilities: As of September 11, 2026, manufacturers of digital products will have an early warning period of 24 hours first appeared on IT-I-Ko.
Manufacturers of software and related equipment that market products in the European Union must, from 11 September 2026, report on vulnerabilities and serious security incidents within 24 hours from the moment they find out about them. The regulation is part of the Cyber Resilience Act (CRA), the European regulation that introduces new requirements [...]
The European Union is now requiring manufacturers to report active cyber vulnerabilities within 24 hours and complete notifications within 72 hours.
The European Union Requires Digital Device Manufacturers to Report Cyberattacks Within 24 Hours
The European Commission and the European Union Cyber Security Agency (ENISA) said new rules requiring reporting of cyberattacks and vulnerabilities will come into force on September 11.
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium








