Producătorii de software și echipamente conectate trebuie să raporteze vulnerabilitățile exploatate

From September 11, 2026, software and connected device manufacturers in the EU must report actively exploited vulnerabilities and serious security incidents within 24 hours. This requirement is part of the Cyber Resilience Act, which aims to enhance security standards for digital products. Following the initial report, companies are required to provide a detailed update within 72 hours. A key challenge for firms will be the timely detection of vulnerabilities, as delays can hinder compliance. The full implementation of the Cyber Resilience Act is set for December 11, 2027, affecting nearly 35,000 software companies in Romania.