EU Cyber Resilience Act ‘completely kills’ manual vulnerability triage
Experts say the EU Cyber Resilience Act’s 24-hour reporting clock makes manual vulnerability triage impractical.
Security experts told CSO Online that the EU Cyber Resilience Act's 24-hour reporting duty for actively exploited vulnerabilities and severe incidents makes manual vulnerability triage impractical. The requirement, introduced on September 11, covers internet-connected hardware and software offered in the EU, including security tools, identity systems, operating systems, routers, firewalls, and VPNs, even when the manufacturer is based outside Europe. Practitioners said SIEM alerts, KEV feeds, scanner findings, asset inventories, and SBOMs must be automated together to identify exploitation in time. Some compared the regime's early incentives to GDPR and warned firms might limit monitoring to reduce reportable findings.