Amenzi de până la 15 milioane EUR, începând de azi, pentru producătorii de software care nu raportează vulnerabilitățile folosite de hackeri. Prima alertă: în 24 de ore - StartupCafe

From September 11, 2026, software and connected device producers must report security vulnerabilities exploited by hackers within 24 hours. A detailed notification is required within 72 hours. Non-compliance with the Cyber Resilience Act can lead to fines up to €15 million or 2.5% of global annual revenue. Micro and small enterprises are exempt from fines for missing the initial 24-hour deadline. The act applies to vulnerabilities actively exploited and severe incidents affecting digital product security. Companies must monitor vulnerabilities continuously and report them through the CRA Single Reporting Platform, operational from the same date. Reporting obligations also apply to products already on the market.