Manufacturers should also notify any severe incident having an impact on the security of the product with digital elements to the CSIRT designated as coordinator and ENISA. In order to ensure that users can react quickly to severe incidents having an impact on the security of their products with digital elements, manufacturers should also inform their users about any such incident and, where applicable, about any corrective measures that the users can deploy to mitigate the impact of the incident, for example by publishing relevant information on their websites or, where the manufacturer is able to contact the users and where justified by the cybersecurity risks, by reaching out to the users directly.
RECITAL 67
Articles discussing this section
- Communication protocols with authorities and customers.
- Steps to be taken immediately after detecting a vulnerability or breach.
- Detailed guidelines on how manufacturers and distributors must handle and report cybersecurity incidents.
- Incident Response Requirements under the CRA
- Role of Incident Reporting under the CRA
Leave a Reply