|
|
|
|
|
by Rygian
14 days ago
|
|
In Europe, the Cyber Resilience Act mandates the manufacturer to: * Report any security breaches within 72 hours to a public body (country's CSIRT + ENISA). * for "all products with digital elements [...] including those already placed on the market before 11 December 2027" Products must be sold with a "secure by default" config, with automated security patching enabled by default (opt-out), with reporting on possible unauthorised access, with data collection minimization (tie-in to GDPR), with an SBOM, with dedicated security testing, with public disclosure of vulnerabilities, … https://digital-strategy.ec.europa.eu/en/policies/cra-summar... |
|