logo

European Council Adopts Cyber Resilience Act

ID: c9120fb9-92c8-50b3-a06c-94b0d4641ae7

STIX ID: report--c9120fb9-92c8-50b3-a06c-94b0d4641ae7

Feed Name: HackerOne Blog

Date Published: 2025-06-27

Date Updated: 2026-06-12

...
...

The EU Council adopted the Cyber Resilience Act (CRA), introducing cybersecurity obligations for manufacturers of software and connected products sold in the EU—including coordinated vulnerability disclosure policies, remediation and security updates, reporting of actively exploited vulnerabilities to CSIRTs and ENISA, and requirements for Software Bill of Materials (SBOM). The regulation will enter into force shortly after publication with most provisions applying three years later and some vulnerability-reporting requirements within 21 months; HackerOne supported improvements for researcher protections but remains concerned about mandatory disclosure of actively exploited vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.