
The European Union has passed a new rule that mandates manufacturers of hardware and software products to report security incidents and exploits within 24 hours of their occurrence.
The rule, which is part of the Cyber Resilience Act (CRA), requires manufacturers, including crypto wallet manufacturers across Europe, to actively provide reports on exploited vulnerabilities and the impact these exploits may have on their products.
Following the submission of an early warning by a manufacturer within 24 hours of a security incident, the manufacturer is also required to submit a full notification to the Computer Security Incident Response Team of the EU Member State where the manufacturer has its main establishment through the Cyber Resilience Act Single Reporting Platform.
Once these initial reports are submitted, the manufacturer must submit a final report no later than 14 days after a corrective or mitigating measure has been made available or implemented. For severe incidents, the report must be submitted within a month.
The new rule became effective on September 11, and according to a press release from the European Union, the ruling is aimed at strengthening the EU’s approach to cybersecurity while also protecting consumers and businesses from cyber threats.
Under Article 64, EU member states can impose penalties ranging from €5 million or 1% of the company’s worldwide annual turnover to as high as €15 million or 2.5% of the company’s annual turnover, depending on whichever option the regulators of that country decide to apply.
Beyond the fines and penalties, EU market surveillance authorities can take corrective or restrictive measures, including requiring products to be brought into compliance, withdrawn from the market, or even recalled.