Cyber Resilience Act. Noi reguli pentru companiile de software din 11 septembrie
From September 11, 2026, software and connected device manufacturers must report actively exploited vulnerabilities under the EU's Cyber Resilience Act. Initial notifications are required within 24 hours of awareness, followed by detailed reports within 72 hours. Nearly 35,000 Romanian companies involved in software development will need to comply, facing challenges in quickly identifying vulnerabilities. The Act mandates security requirements for digital products and applies to those on the market before the full implementation date of December 11, 2027. Reporting will be done through a platform managed by ENISA, emphasizing the need for updated inventories and monitoring of security information.