EU launches 24-hour reporting rule for actively exploited cyber vulnerabilities
The EU's ENISA-run portal now obliges manufacturers to publish exploited flaws and serious security incidents within 24 hours of learning they are being used.
Under a recently adopted EU rule, manufacturers of digital goods marketed in the Union must report any actively exploited security flaws and serious incidents through ENISA's central online portal. The requirement applies to firms worldwide, including those from the United States, China, Japan or South Korea. Reporting starts when the vendor learns that a vulnerability is being used, not when it is first discovered; an early warning must be posted within 24 hours, a more detailed notice within 72 hours, and a comprehensive report within two weeks (extended to one month for severe cases).
The rule does not mandate fixing the flaw within those timeframes, but it may compel firms to notify users and supply available fixes or mitigations without undue delay. Non-compliance can lead to tiered fines, though specific amounts are not detailed in the source. The measure aims to accelerate information sharing and help organizations implement risk-reduction steps promptly.
Why it matters
Quicker disclosure of exploited bugs lets EU users and companies act fast against cyber threats.
In this story
