news.mlab.sh
Back to the feed
threat-intel

EU Cyber Resilience Act to Enforce New Reporting Requirements

High
Summary

The EU Cyber Resilience Act (CRA) is being implemented with a rapid change: starting September 11th, businesses selling products in EU member states must report actively exploited vulnerabilities or severe security incidents within 24 hours. Failure to comply could result in fines of up to 15 million euros. While smaller vendors are exempt, larger organizations face significant penalties. Despite the strict reporting requirements, the CRA is relatively lenient, excluding reporting for known but unexploited vulnerabilities and allowing for security by obscurity in certain circumstances. The CRA emphasizes incident detection and response capabilities, with the potential for fines to be lower than the maximum stated.

The EU Cyber Resilience Act (CRA) is being rolled out with a significant and immediate change to cybersecurity reporting requirements. Beginning September 11th, any organization that distributes products within the European Union will be required to report actively exploited vulnerabilities or any severe security incidents impacting the availability, authenticity, integrity, or confidentiality of sensitive data within just 24 hours. This represents a substantial shift in how businesses operate and manage security incidents.

Organizations selling products in EU member countries are subject to these regulations, regardless of where they are headquartered. Hardware and software are both included under the CRA’s scope. Notably, microenterprises (fewer than 10 employees and less than 2 million euros in annual turnover) and small enterprises (fewer than 50 employees and 10 million euros) are exempt from the 24-hour reporting window. However, larger organizations face potentially substantial fines, up to 15 million euros, or 2.5% of their total worldwide annual revenue if that amount exceeds 15 million.

The CRA is not without its nuances. It does not require reporting for known but not yet actively exploited vulnerabilities, even if those vulnerabilities are severe. Furthermore, Article 16(2) allows for a period of delay in dissemination of notifications, based on justified cybersecurity-related grounds, particularly upon request by the manufacturer and considering the sensitivity of the information.

According to Dr. Aram Hovsepyan, CEO and founder of Codific, the maximum penalties outlined in the CRA are likely to be lower than those typically imposed under GDPR. He emphasizes that organizations need to prioritize robust incident detection and response capabilities, with many large companies already having dedicated incident response teams and clear playbooks in place. However, he acknowledges that during a security incident, organizations are often more concerned with mitigating reputational damage than strictly adhering to compliance regulations.

Read the full article at Dark Reading