Regulation (EU) 2024/2847, in force since December 2024 with phased obligations running to December 2027. Sets mandatory cybersecurity requirements for hardware and software products with digital elements placed on the EU market, including vulnerability handling and a duty to report actively exploited vulnerabilities to ENISA within 24 hours. The strongest-performing term found across the whole build, with rising, correctly targeted search volume that neither the AI Act nor GDPR terms have matched.
