Skip to content
tag — compliance

grep -rl "compliance" ./articles

#compliance

9 articles

Europe's 24-hour exploit-reporting clock reaches products sold years ago. Its security rules do not

2026-09-15World

Since 11 September, manufacturers selling connected products in the EU must warn authorities within 24 hours of learning that a flaw in one is being exploited. The Cyber Resilience Act applies that duty to products already on the market, while its security requirements reach only those placed on the market from December 2027. For a device already on sale, the Act now requires the report, but not the patch.

India's banking regulator issued seven cybersecurity directions at once, and they were already in force when you read about them

2026-08-27World

On 31 July the RBI published parallel Cybersecurity, Technology: Risk, Resilience and Assurance Framework Directions for commercial banks, small finance banks, payments banks, urban co-operative banks, financial institutions, NBFCs and credit information companies. They took effect immediately, they repeal what came before, and incidents must reach the RBI within six hours.