For the CVE points, I'd expect enforcement to be difficult. Might also create perverse incentives, like if you neglect to patch, it might be better to never patch in the hopes no-one notices, since patching late would draw attention to your not having done so promptly and result in fines.
As for the automatic updates, personally, I view the vendor as the biggest threat. I'd prefer they didn't have any access to my gear. Which is one reason, in addition to just never having seen anything useful, I don't have "smart" appliances.
As for the automatic updates, personally, I view the vendor as the biggest threat. I'd prefer they didn't have any access to my gear. Which is one reason, in addition to just never having seen anything useful, I don't have "smart" appliances.