If the law wouldn't say 24 hours counting only working hours (3 working days for small business or even weeks during vacations), then it wouldn't be an exempt.
https://www.enisa.europa.eu/topics/product-security/single-r...
> Reporting process starts at the moment manufacturer becomes aware of active exploitation of vulnerability or incident.
If your business is closed (due to vacation or sickness for example) you don't become aware until you are back.
I think it only hurts super small one man part time developers but even then: If I pay for a piece of software I expect it to be secure and have a bit of support.