Stay up to date with the latest developments around the Cyber Resilience Act.
The CRA's incident and vulnerability reporting obligations apply from 11 September 2026 through the ENISA Single Reporting Platform. ENISA has published FAQs, a two-page factsheet and step-by-step guidance on registering and submitting notifications. ENISA also released its Secure by Design and Default Playbook — 22 practical playbooks covering the full product life cycle — and international partners published the 2026 Minimum Elements for a Software Bill of Materials (SBOM).
The European Commission has published its official guidance on Cyber Resilience Act implementation. It clarifies product scope — including remote data processing solutions and free and open source software — what counts as a 'substantial modification', how support periods apply, and reporting and risk-assessment obligations. It includes 67 practical examples, use cases and flowcharts aimed at SMEs and microenterprises.
ENISA has updated its FAQ on the CRA Single Reporting Platform, including the data fields manufacturers must provide when reporting incidents under Article 14. In addition, a public consultation on a draft technical advisory on secure update mechanisms for SMEs is open until 10 July 2026.
OpenSSF submitted community feedback on two EU consultations: the revision of the Cybersecurity Act and amendments to the NIS2 Directive. Input was also provided on ENISA's 'Secure by Design' playbook for SMEs.
ENISA published a draft playbook to help SMEs embed security from the design stage. It provides practical steps for engineering, product and release processes.
The CRA entered into force on December 10, 2024. Manufacturers, importers and distributors of products with digital elements must comply with the new requirements before December 11, 2027.
CRA legislation is still evolving. Contact us for the latest insights.
Our specialists are happy to assist you with your compliance journey.