Hacker News new | ask | show | jobs
by Rygian 14 days ago
In Europe, the Cyber Resilience Act mandates the manufacturer to:

* Report any security breaches within 72 hours to a public body (country's CSIRT + ENISA).

* for "all products with digital elements [...] including those already placed on the market before 11 December 2027"

Products must be sold with a "secure by default" config, with automated security patching enabled by default (opt-out), with reporting on possible unauthorised access, with data collection minimization (tie-in to GDPR), with an SBOM, with dedicated security testing, with public disclosure of vulnerabilities, …

https://digital-strategy.ec.europa.eu/en/policies/cra-summar...