On 11 September, the EU Cyber Resilience Act made it official: an actively exploited vulnerability must be reported within 24 hours. It joins a run of rules that all point the same way. When a flaw is being used against you, you have hours to respond, not weeks. Google’s threat researchers counted 75 zero-day vulnerabilities exploited in the wild in 2024, and nearly half targeted enterprise systems. Here is what the standards require, and why the part most organisations get wrong is how fast they find out.
Zero-day vs cyber incident
A zero-day is a vulnerability with no patch available, often because the vendor does not yet know it exists. The name refers to the time the vendor has had to fix it: zero days. A cyber incident is an event that compromises, or seriously threatens, your systems or data, such as ransomware, a breach or an outage caused by an attack.
A zero-day becomes your problem only when it is exploited against you, and at that point you have an incident. Most incidents involve no zero-day at all: stolen credentials and known, unpatched flaws cause far more of them. The distinction matters for compliance, because most rules trigger on the incident, while the Cyber Resilience Act focuses on the exploited vulnerability itself.
Why zero-days break the normal playbook
The usual defensive cycle assumes a patch exists. With a zero-day it does not, so detection and containment carry the load alone. Two trends make that harder.
Exploitation now often precedes the fix. The median time from disclosure to exploitation fell from 63 days in 2018 to 32 days in 2022, and Mandiant’s analysis of 2024 vulnerabilities found the average had turned negative, meaning attacks were frequently seen before a patch was public.
Attackers have moved to the perimeter. In Verizon’s 2025 Data Breach Investigations Report, exploitation of vulnerabilities rose 34 percent as an entry route and reached about 20 percent of breaches. Edge devices and VPNs made up 22 percent of those exploitation breaches, up almost eightfold from 3 percent a year earlier, and only 54 percent of those flaws were fully patched. The most exposed devices are hit fastest, often before a fix exists.
What the standards require, in Europe and the Gulf
Several frameworks now converge on fast, mandatory notification to a national authority. The clocks differ, but the message is the same.
| Framework | Applies to | Reporting clock |
|---|---|---|
| EU Cyber Resilience Act | Makers of products with digital elements | 24h early warning, 72h notification, 14-day final report |
| NIS2 | Essential and important entities | 24h early warning, 72h notification, 1-month report |
| DORA | Financial entities | 4h after major classification, 72h, 1 month |
| ISO/IEC 27001:2022 | Certified organisations | No statutory clock; threat intelligence required (control 5.7) |
| UAE ADGM FSRA | Financial entities in ADGM | 24h for material cyber incidents |
| Saudi Arabia (NCA, SAMA, SDAIA) | By sector and data type | Multiple clocks; 72h under the PDPL |
| Qatar (NIA, Q-CERT) | Government and regulated entities | Mandatory, tier-dependent |
Different regulators, one message: report fast, or the delay itself becomes the violation. In the Gulf the exact hour thresholds are often tier-dependent, but the direction is identical. DORA and ISO/IEC 27001:2022 go further and make threat intelligence an explicit requirement rather than optional good practice.
How fast you find out
Read together, these regimes ask for the same thing: detect, assess and report at speed. The hard part is rarely the report template or the legal channel. It is how quickly you learn that a flaw is being exploited, and whether it affects you.
A 24-hour clock is unworkable if you find out on day three. When exploitation frequently precedes the patch, a routine scan or a vendor advisory arrives too late. The organisations that meet these obligations are the ones that shorten the distance between a flaw being exploited somewhere and their own team knowing about it.
How EXEO helps
This is where early warning matters, and the reason DORA and ISO/IEC 27001:2022 now name threat intelligence directly. EXEO’s Argos service scans vulnerability databases, security research and vendor advisories every day, matches each finding against your registered critical assets, and has an EXEO analyst grade its real severity before it reaches you. You learn early when a flaw relevant to your environment is being exploited, ranked by real exposure.
It helps in two directions. Fewer zero-days turn into incidents, and when one does, there is enough lead time to meet the reporting deadline instead of missing it. EXEO can also help you map which of these clocks bind your organisation and build the reporting path before you need it.
Frequently Asked Questions
What is the difference between a zero-day and a cyber incident?
A zero-day is a vulnerability with no patch available, often because the vendor does not yet know it exists. A cyber incident is an event that actually compromises your systems or data. A zero-day becomes an incident only when it is exploited against you.
What did the EU Cyber Resilience Act change on 11 September 2026?
Since 11 September 2026, makers of products with digital elements must report an actively exploited vulnerability to ENISA within 24 hours, followed by a notification within 72 hours and a final report within 14 days.
What are the NIS2 reporting deadlines?
NIS2 requires essential and important entities to send a 24-hour early warning, a 72-hour notification and a final report within one month for significant incidents.
What does DORA require for incident reporting?
Financial entities must report a major ICT incident within four hours of classifying it, with an intermediate report at 72 hours and a final report within one month. DORA also requires threat-led penetration testing and encourages threat-intelligence sharing.
Are there similar rules in the Middle East?
Yes. The UAE ADGM FSRA framework requires 24-hour reporting of material cyber incidents, the UAE PDPL adds a 72-hour breach notification, and Saudi Arabia and Qatar run their own mandatory reporting to national authorities. Exact thresholds are often tier-dependent.
How fast are zero-days actually exploited?
Faster than patches ship. The median time to exploit fell from 63 days in 2018 to 32 days in 2022, and Mandiant found the 2024 average had turned negative, meaning exploitation is now often observed before a patch is public.
How does EXEO help us meet these deadlines?
EXEO’s Argos threat intelligence gives early warning when a vulnerability relevant to your environment is being exploited, and EXEO can map which reporting clocks apply to you and help build the response path in advance.
See the threat coming
Zero-days will keep arriving faster than patches. The rules have adjusted to that. Talk to EXEO about threat intelligence and regulatory readiness across the EU and the Gulf.

