The National Cyber Security Centre (NCSC) has published guidelines for businesses as new rules on products with a digital element come into effect across the EU today (11 September).
From today, manufacturers must report significant vulnerabilities and incidents that affect the security of their products through the EU's Cyber Resilience Act (CRA) reporting framework.
The Department of Justice says that the National Cyber Resilience Act Guidelines provide practical support for manufacturers covered by the regulations.
The guidelines contain information on reporting thresholds, timelines, notification procedures, and the information required when submitting reports.
Dr Richard Browne (director general of the NCSC) said that today marked “a significant milestone” in European cyber-security regulation.
“The commencement of the Cyber Resilience Act's reporting obligations will improve visibility of vulnerabilities and incidents affecting connected products and strengthen our collective ability to respond to emerging cyber threats,” he stated.
Under the rules, manufacturers who become aware of an actively exploited vulnerability or a severe incident affecting the security of a product with digital elements must report that information through the CRA platform.
Initial notifications are required within 24 hours of becoming aware of a reportable event.
The CRA establishes a common framework for improving the cyber-security of products with digital elements throughout their lifecycle. It will apply in full from 11 December 2027.