The EU CRA's Real Question: What Shipped, and When Did You Know?
欧盟《网络韧性法案》漏洞报告要求将于 9 月 11 日生效,软件供应商需在最短时间内上报已利用的漏洞。ActiveState 指出,明确已知悉漏洞发现时间及具体发布版本是满足新规的关键。该法案规定供应商需在极短窗口期内(如 24 小时)报告活跃利用的缺陷。
EVENT DOSSIER
The requirements for reporting vulnerabilities under the EU’s “Network Resilience Act” will come into effect on September 11, imposing strict compliance obligations on software suppliers. The new regulations require suppliers to report exploited vulnerabilities within a very short window period (such as 24 hours). ActiveState notes that the key to meeting these regulations lies in clearly disclosing the specific time when the vulnerabilities were known and the version of the software that was affected.
欧盟《网络韧性法案》漏洞报告要求将于 9 月 11 日生效,软件供应商需在最短时间内上报已利用的漏洞。ActiveState 指出,明确已知悉漏洞发现时间及具体发布版本是满足新规的关键。该法案规定供应商需在极短窗口期内(如 24 小时)报告活跃利用的缺陷。