European Council Adopts Cyber Resilience Act
ID: c9120fb9-92c8-50b3-a06c-94b0d4641ae7
STIX ID: report--c9120fb9-92c8-50b3-a06c-94b0d4641ae7
Feed Name: HackerOne Blog
The EU Council adopted the Cyber Resilience Act (CRA), introducing cybersecurity obligations for manufacturers of software and connected products sold in the EU—including coordinated vulnerability disclosure policies, remediation and security updates, reporting of actively exploited vulnerabilities to CSIRTs and ENISA, and requirements for Software Bill of Materials (SBOM). The regulation will enter into force shortly after publication with most provisions applying three years later and some vulnerability-reporting requirements within 21 months; HackerOne supported improvements for researcher protections but remains concerned about mandatory disclosure of actively exploited vulnerabilities.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
