kras99 - stock.adobe.com

EU cyber rule exposes gaps in product security operations

Europe's new reporting rule could establish a global product security standard, but smaller manufacturers and legacy products face the steepest challenge.

The EU's 24-hour vulnerability reporting clock is now running for manufacturers of connected hardware and software. Under the new reporting provisions, product-security teams must quickly determine whether a flaw is present in a shipped product and under active exploitation.

The reporting provisions of the EU's Cyber Resilience Act (CRA) took effect September 11. It requires manufacturers to submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability or severe security incident, followed by a fuller notification within 72 hours.

Final reports are due within 14 days after a corrective measure becomes available for a vulnerability or within one month of the 72-hour notification for a severe incident. The requirements cover products already on the EU market; most other CRA provisions take effect December 11, 2027.

The new European reporting rule could establish a global product-security standard, but it will be difficult for smaller manufacturers and legacy products to meet its provisions.

Can security teams meet the 24-Hour deadline?

The real test is whether manufacturers can verify that a vulnerability affects a shipped product and can be exploited before the deadline expires, said Katie Norton, research director for cloud security at research firm IDC.

"Before a company can report in 24 hours, it must know which products contain the affected component, where they're deployed and whether the flaw is genuinely exploitable in its own product rather than just present in a dependency," Norton said. "That last judgment takes engineering, not a scanner."

That requires component inventories extending back to older products, a written procedure specifying who can determine whether the threshold has been met and on-call coverage through weekends and holidays.

Laura Heuvinck, spokesperson for the EU Agency for Cybersecurity (ENISA), said the staged process accommodates information that changes during an investigation.

"The CRA reporting process is intentionally progressive," Heuvinck said. "The 24-hour early warning provides the information available at that stage, while the 72-hour notification and final report allow further detail and updates as the investigation develops."

The early warning serves as a signal, but manufacturers must still distinguish confirmed exploitation from theoretical exposure fast enough to make it useful.

CRA's reach extends beyond Europe

The new rules focus on manufacturers and exploited product vulnerabilities. They exceed current U.S. reporting requirements, according to Doc McConnell, head of policy and compliance at Finite State and a former branch chief at the Cybersecurity and Infrastructure Security Agency, part of the U.S. Department of Homeland Security.

It's already turning into the practical baseline. I expect manufacturers selling into the EU won't run one product-security process for Europe and a weaker one everywhere else.
Doc McConnellHead of policy and compliance at Finite State

"This is a stricter standard by far than the current requirements in the U.S.," McConnell said. "The closest U.S. analog is the Cyber Incident Reporting for Critical Infrastructure Act."

CIRCIA applies to covered critical infrastructure entities and focuses on organizational incidents. Other similar requirements include Securities and Exchange Commission rules that address public companies and material incidents. The CRA operates at the product level across a broader range of hardware and software.

"It's already turning into the practical baseline," McConnell said. "I expect manufacturers selling into the EU won't run one product-security process for Europe and a weaker one everywhere else." 

The CRA's reach extends beyond companies headquartered in Europe, said SANS Institute certified instructor Jan D'Herdt. "The CRA applies to products sold into the EU regardless of where the manufacturer is located," he said.

Companies in North America, Asia-Pacific, the Middle East and elsewhere that wish to access the EU market might adopt CRA-aligned processes globally rather than maintain separate regional workflows, D'Herdt said. For instance, manufacturers selling digital products in the EU might find it simpler to adopt one reporting process across their operations, he added.

"The combination of secure-by-design requirements, lifecycle vulnerability management, reporting obligations and supply-chain accountability could make the CRA an influential benchmark for future global product-security regulations," D'Herdt said.

Smaller manufacturers face a compliance burden

The compliance burden will fall unevenly because the work is determined by the number and age of a manufacturer's products rather than its head count or revenue, IDC's Norton explained.

"The work scales with the number of products, not the size of the company," Norton said. "A five-person firm and a 5,000-person firm with the same three products face roughly the same job and only one has a compliance function."

Microenterprises and small manufacturers can't be fined solely for missing the 24-hour deadline, but the reporting obligation and subsequent stages still apply. Smaller companies might lack dedicated product-security personnel, continuous monitoring and legal staff able to review a filing at short notice.

Older products present another problem: Developers might have left, suppliers could no longer support components and build environments can be impossible to recreate. Manufacturers might need to reconstruct inventories from shipped software or firmware.

Compliance also might draw engineers away from development or discourage smaller companies from entering the EU market. ENISA offers implementation guidance tailored to small-and-medium-sized enterprise constraints, but it can't supply missing personnel or product knowledge.

A regulation designed to make connected products safer could, as a side effect, make it harder for smaller or newer players to compete with parties that can absorb the compliance cost more easily, cautioned SANS's D'Herdt.

Noncompliance carries fines up to €15 million ($17.3 million) or 2.5% of worldwide annual turnover.

"This is far more punishing for a small manufacturer's financial position than for a large one, even though the percentage is the same," D'Herdt said.

How CISOs can prepare for full CRA compliance

There are several ways CISOs can ready their organizations for compliance.

Supplier notifications can flow through the product chain and impose obligations on other manufacturers, said Michelle Abraham, senior research director in IDC's Security and Trust Group. "CISOs and those involved in third-party risk management should ensure the CRA evidence requirements are included in their supply chain contracts," she said.

Those contracts should define the evidence suppliers must provide and require that notifications be made early enough for manufacturers to meet their own deadlines.

CISOs and security teams also need accurate asset inventories with up-to-date context, including when a product is no longer supported, Abraham said.

"There should be an intake workflow that connects the exploit notification to incident triage, enabling rapid action on the new information," she said. "Once the affected asset is identified, the asset context will inform the priority of the work."

That workflow may include a threat hunt looking for a previously unknown intrusion.

When a vulnerability can't be immediately remediated or mitigated, the affected system should be monitored for signs of attack with updated detection logic, Abraham said.

While the CRA sets an essential baseline, it should not be seen as the ultimate destination for cyber resilience.
Heigor FreitasHead of region for the UK and Europe at the Council of Registered Ethical Security Testers

Heigor Freitas, head of region for the UK and Europe at the Council of Registered Ethical Security Testers, said the reporting requirement should strengthen accountability before the wider CRA takes effect in December 2027.

However, from his perspective, compliance merely represents the starting point for product security.

"While the CRA sets an essential baseline, it should not be seen as the ultimate destination for cyber resilience," he cautioned. "In any case, more mature and resilient organizations shouldn't be caught off guard by this new regulation."

Organizations with established standards, independent assurance and transparent reporting practices will be better prepared for both the CRA and later regulatory changes Freitas said.

"Industry leaders don't wait for regulation to comply," he added. "They continuously look beyond legal minimums."

Nathan Eddy covers IT trends and technologies across multiple industries. Eddy is a graduate of Northwestern University's Medill School of Journalism. He's also a documentary filmmaker, specializing in architecture and urban planning. He currently lives in Berlin, Germany.

Dig Deeper on CISO Strategy & Planning