Bottom line: Companies in the EU must prioritize product security and vulnerability disclosure under the new regulations, or risk facing penalties.
What's happening: The Cyber Resilience Act requires companies to submit detailed reports on their vulnerability management practices and product security measures, including the identification of high-risk vulnerabilities with a CVSS score of 7.0 or higher.
What to do: Security leaders must review their company's vulnerability disclosure and product security policies, ensuring compliance with the CRA's reporting requirements and updating their incident response plans accordingly.