Manufacturers of products with digital elements (hardware and software, including SaaS-connected devices and standalone apps) must report actively exploited vulnerabilities and severe security incidents through ENISA's single reporting platform: early warning within 24 hours, full notification within 72 hours, final report within 14 days (vulnerabilities) or one month (incidents). It applies to products already on the market.
Who is affected
Any manufacturer that sells software or connected hardware in the EU, including small software vendors and open-source projects run commercially. Non-commercial open source is largely exempt.
Sizes: micro, small, medium, large · Sectors: Software / SaaS, Hardware / electronics, Manufacturing · Applies if: We make connected hardware / devices; We sell online
What to do
Set up an internal process to detect and triage exploited vulnerabilities and incidents in your products. Register on the ENISA single reporting platform and identify your national CSIRT. Draft report templates and an on-call rota so you can meet the 24h/72h clocks. Inform affected users of fixes.
Manufacturers, importers and distributors of software and connected hardware sold in the EU, including small SaaS vendors that ship client software, IoT makers and app developers.