BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//EU Deadline Radar//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-WR-CALNAME:EU Deadline Radar
NAME:EU Deadline Radar
BEGIN:VEVENT
UID:cra-vulnerability-incident-reporting@eudeadlines.eu
DTSTAMP:20260907T211049Z
DTSTART;VALUE=DATE:20260911
DTEND;VALUE=DATE:20260912
SUMMARY:Cyber Resilience Act: CRA: mandatory reporting of actively exploite
 d vulnerabilities and severe incidents to ENISA/CSIRT
DESCRIPTION:Manufacturers of products with digital elements (hardware and s
 oftware\, including SaaS-connected devices and standalone apps) must repor
 t actively exploited vulnerabilities and severe security incidents through
  ENISA's single reporting platform: early warning within 24 hours\, full n
 otification within 72 hours\, final report within 14 days (vulnerabilities
 ) or one month (incidents). It applies to products already on the market.\
 n\nWho is affected: Any manufacturer that sells software or connected hard
 ware in the EU\, including small software vendors and open-source projects
  run commercially. Non-commercial open source is largely exempt.\n\nWhat t
 o do: Set up an internal process to detect and triage exploited vulnerabil
 ities and incidents in your products. Register on the ENISA single reporti
 ng platform and identify your national CSIRT. Draft report templates and a
 n on-call rota so you can meet the 24h/72h clocks. Inform affected users o
 f fixes.\n\nPenalty: Up to €15M or 2.5% of worldwide turnover\n\n\nStatu
 s: Confirmed\nhttps://eudeadlines.eu/deadline/cra-vulnerability-incident-r
 eporting
URL:https://eudeadlines.eu/deadline/cra-vulnerability-incident-reporting
CATEGORIES:EU,Cyber Resilience Act
LAST-MODIFIED:20260907T000000Z
TRANSP:TRANSPARENT
END:VEVENT
END:VCALENDAR
