Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Those will obviously be exempt?


If the law wouldn't say 24 hours counting only working hours (3 working days for small business or even weeks during vacations), then it wouldn't be an exempt.


No you misunderstood it:

https://www.enisa.europa.eu/topics/product-security/single-r...

> Reporting process starts at the moment manufacturer becomes aware of active exploitation of vulnerability or incident.

If your business is closed (due to vacation or sickness for example) you don't become aware until you are back.


This is an interesting point of view. I've been thinking that only the moment counts, when the manufacturer has been made aware, regardless when the manufacturer has in fact actively become aware. Thanks!


I have a lot of contact with the CRA at work and I actually think its a very good piece of regulation. There are barely any parts where I think they are straight up bad.

I think it only hurts super small one man part time developers but even then: If I pay for a piece of software I expect it to be secure and have a bit of support.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: