24h Reporting: How to Declare a Vulnerability to ENISA under the CRA
The CRA requires notifying ENISA within 24h of a breach. Learn how to prepare your incident response plan.
The CRA requires notifying ENISA within 24h of a breach. Learn how to prepare your incident response plan.
Responsiveness is the new legal standard. The CRA requires manufacturers to notify ENISA of any exploited vulnerability within 24 hours of detection.
This extremely short timeframe leaves no room for improvisation. Your company must have pre-established communication channels and a team ready to act at all times.
Detection and triage of vulnerabilities must be automated to allow rapid submission of reports that meet ENISA requirements. Delay can lead to fines of up to β¬10M.
24h reporting is the major operational challenge of the CRA. Don't risk a fine for late notification.