The regulatory map for AI-era vulnerability management.
Four regimes now govern how organizations must find, prioritize, and report vulnerabilities — two already in force with hard deadlines this year, one arriving in 2027, and one that's voluntary but increasingly consequential. Each hub below is a practitioner-grade guide maintained against primary sources.
Tell us what you're trying to solve and we'll connect you with a vetted partner.
Four-variable risk model, 72-hour critical tier, forensic triage requirement. Agency policy deadline August 7, 2026.
A hard legal mandate, not voluntary coordination: manufacturers of products with digital elements sold into the EU must report actively exploited vulnerabilities within 24 hours. Applies to non-EU companies too.
Certification revocation after March 7, 2027. Exceeds BOD 26-04 in key respects, including the "Assume It's Automatable" standard.
Deferred to December 2, 2027 (Annex III) and August 2, 2028 (embedded systems) by the Digital Omnibus, formally adopted June 2026. The deferral is preparation runway, not a reprieve: conformity assessment requirements remain extensive.