Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Politics

EU launches 24-hour reporting rule for actively exploited cyber vulnerabilities

The EU's ENISA-run portal now obliges manufacturers to publish exploited flaws and serious security incidents within 24 hours of learning they are being used.

Under a recently adopted EU rule, manufacturers of digital goods marketed in the Union must report any actively exploited security flaws and serious incidents through ENISA's central online portal. The requirement applies to firms worldwide, including those from the United States, China, Japan or South Korea. Reporting starts when the vendor learns that a vulnerability is being used, not when it is first discovered; an early warning must be posted within 24 hours, a more detailed notice within 72 hours, and a comprehensive report within two weeks (extended to one month for severe cases).

The rule does not mandate fixing the flaw within those timeframes, but it may compel firms to notify users and supply available fixes or mitigations without undue delay. Non-compliance can lead to tiered fines, though specific amounts are not detailed in the source. The measure aims to accelerate information sharing and help organizations implement risk-reduction steps promptly.

Why it matters

Quicker disclosure of exploited bugs lets EU users and companies act fast against cyber threats.

In this story

EU cybersecurity ruleENISA reporting platformactively exploited vulnerability24-hour disclosuredigital product manufacturerssecurity incident reportinguser notificationmitigation guidance
Get the beta ↗