EU Cyber Resilience Act: 24-Hour Breach Reporting Starts Today
Starting today, any organisation that sells internet-connected products in the EU must report actively exploited vulnerabilities or serious security incidents to ENISA (the European Union Agency for Cybersecurity) within 24 hours of discovery, per Dark Reading. A fuller notification is due within 72 hours. Missing the window risks fines of up to €15 million or 2.5% of global annual revenue. Physical location doesn't matter — if you sell into EU markets, this applies to you. Small enterprises under 50 employees have limited exemptions; larger organisations do not.
Sources

