Medical device makers face 24-hour flaw reports in Europe

Manufacturers selling digital products in the EU must now report actively exploited flaws within 24 hours.

MedRisk Staff
By
2 Min Read

Manufacturers selling any product with digital elements in the EU, including medical devices, clinical software and connected diagnostics, must now report actively exploited vulnerabilities to authorities within 24 hours.

The reporting duties in Article 14 of the Cyber Resilience Act took effect on September 11. Companies must file an early warning within 24 hours of learning of an exploited flaw, a fuller notification within 72 hours, and a final report within 14 days of shipping a fix. Serious security incidents carry the same 24-hour and 72-hour deadlines, with a final report due after one month. The rules bind non-EU manufacturers too, and reports go through ENISA’s Single Reporting Platform to a designated computer security incident response team.

Breaching the duties counts as a core obligation under the act, exposing companies to fines of up to 15M euros or 2.5 percent of global turnover, whichever is higher.

For medical device makers, the CRA layers a second reporting track on top of existing EU medical device rules, and it covers the software and connectivity that regulators flag as the fastest-growing attack surface in health technology. Hospitals should expect faster, clearer advisories about flaws in the devices they run, and should ask suppliers who owns CRA notifications.

Security leaders at medtech firms should map the 24-hour clock to an internal escalation path now, before the first exploited flaw forces a rushed filing.

Share This Article