Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform

Manufacturers selling products with digital elements in the EU must now report actively exploited vulnerabilities to cybersecurity authorities under the Cyber Resilience Act's mandatory reporting rules.The reporting duties set out in Article 14 of the CRA became applicable today. Subject to the regulation's exemptions, they apply to manufacturers of products with digital elements made available in the EU, regardless of where those manufacturers are based.Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a more detailed notification within 72 hours.

The same deadlines apply to severe incidents affecting the security of products with digital elements.

The only difference in timing is related to the final report. Manufacturers must provide a final report on an actively exploited vulnerability within 14 days of making a corrective or mitigating measure available. For serious incidents, the final report is due one month after the first report.Darren Anstee, CTO for security at Netscout, said the reporting deadlines introduce much-needed urgency in working toward global cyber resilience."The 24-hour window in which an initial warning must be reported creates a level of urgency, with subsequent deadlines ensuring that the gathering and release of additional information is prompt," he said."Better, more rapid sharing of information helps organisations put defences and mitigating controls in place when they know there is heightened risk."EU and non-EU manufacturers must file these reports through ENISA's Single Reporting Platform (SRP).Notifications are addressed to the coordinating computer security incident response team (CSIRT) determined under the CRA. For an EU manufacturer, this is generally the CSIRT for the member state where it has its main establishment; separate rules determine the coordinator for manufacturers based outside the bloc.Manufacturers must also inform affected users, where appropriate, about actively exploited vulnerabilities or severe incidents. The CRA states that users must be informed of available corrections or mitigations without undue delay.Generally, failures under the CRA are punishable by varying tiers of fines, the most serious of which can reach €15 million ($17.4 million) or 2.5 percent of the offender's annual turnover, whichever is higher.