EU rules on securing IT products begin this week, but enterprises aren’t ready
ID: 1bed1933-c552-547c-a423-52532db8e223
STIX ID: report--1bed1933-c552-547c-a423-52532db8e223
Feed Name: CIO Security
The text summarizes the Cyber Resilience Act (CRA) requirements and timelines: conformity assessment bodies designated from June 11, mandatory vulnerability reporting by manufacturers from September 11, and remaining obligations (including fines up to €15 million or 2.5% of global turnover) effective December 11, 2027. It highlights the creation of an open-source steward role to manage software security policies and cites an OpenSSF survey finding that 56% of respondents were unaware of the potential fines, underscoring a gap in organizational preparedness.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
