No. 75: CRA Reporting: Must Your Team Be On Duty 24/7?
A common claim: From 11 September 2026, manufacturers must have a cybersecurity team on duty 24/7 to submit early warning notifications within 24 hours. No matter how many cybersecurity professionals claim this, it's wrong!
Read next
How Can Manufacturers Address and Remediate 1000+ CVEs?
Fixing 1000+ CVEs one by one is too costly. Filtering them is arbitrary and might miss important ones. Making the exploitation of hundreds of CVEs unlikely by multiple security measures in one go is nothing else but defence in depth!
Understanding the CVSS Metrics for Exploitability
Instead of fixing hundreds of CVEs, manufacturers can provide enough security measures to make the exploitation unlikely. The decrease of the CVSS metrics is a useful indicator how effective the security measures are. This post is about understanding the CVSS metrics.