CRA vulnerability reporting

CRA September 2026: 24-Hour Vulnerability Reporting

From 11 September 2026, every software manufacturer selling into the EU has to report an actively exploited vulnerability within 24 hours of becoming aware of it. Not 24 business hours. Twenty-four hours.