Hi Adam,
Today, the CRA-clock starts.
As of today, reporting exploited vulnerabilities and serious product security incidents is mandatory under the EU Cyber Resilience Act (CRA). If someone exploits an open CVE in your device, you now only have 24 hours to report it and 72 hours for a severe incident.
Can your team tell, right now, which of your open CVEs are at risk of exploitation?
For embedded teams, that’s often easier said than done.
Long CVE lists make it difficult to quickly separate noise from real risk. When reporting deadlines are measured in hours, there’s little room for guesswork.
Take the guesswork out of CRA compliance with Torizon.
Don't know your exposure? Talk to our experts and let's check together: book your 1:1 consultation.
Best regards,
Team Torizon