News & updates

CRA news and developments

Stay up to date with the latest developments around the Cyber Resilience Act, EU cybersecurity regulation and compliance best practices.

Recent articles

March 24, 2026

Germany mandates ODF for sovereign digital infrastructure — CRA-Portal adds ODF export

Germany's "Deutschland-Stack" initiative now requires the Open Document Format (ODF) as the mandatory document standard for all federal agencies. For manufacturers selling CRA-regulated products to German government bodies, this means compliance documentation must be delivered in ODF-compatible formats to integrate with public procurement workflows. CRA-Portal.eu has responded by adding full ODF export for compliance dossiers, making it the first CRA compliance platform to support this format. The feature ensures that technical files, risk assessments and conformity declarations can be exported directly in ODF, removing friction for suppliers navigating both CRA obligations and German digital sovereignty requirements.

March 3, 2026

Draft CRA Guidance published for public consultation

The European Commission has published draft guidance on the Cyber Resilience Act, covering key topics including free and open-source software, remote data processing solutions, core functionality, placing on the market of software, and risk assessment. The public consultation is open until March 31, 2026 via the Have Your Say portal.

March 3, 2026

ENISA opens applications for Security Architecture Working Group

ENISA has opened applications for an Ad-Hoc Working Group on Security Architecture Engineering and Vulnerability Management. The group will support ENISA's activities in security architecture for digital products and developing EU vulnerability management capacity. Application deadline: April 15, 2026.

Earlier articles

March 3, 2026

Stan4CRA launches webinar series on CRA standards

The Stan4CRA project is hosting a series of webinars and deep dives on European harmonised standards under development in support of the CRA. The events cover practical implementation guidance for manufacturers, importers and distributors preparing for compliance.

January 15, 2026

CRA reporting obligations take effect September 2026

Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe security incidents to ENISA within 24 hours. Organizations should begin preparing their incident reporting procedures now to ensure readiness.

December 3, 2025

European Commission publishes CRA implementation guidance

The European Commission has released detailed guidance documents to help economic operators understand and implement CRA requirements. The guidance covers product classification, conformity assessment procedures and SBOM requirements.

Subscribe to our newsletter

Receive monthly updates on CRA developments, regulatory changes and compliance tips directly in your inbox. No spam — only relevant, actionable information.

Questions about recent CRA developments?

Our specialists monitor all CRA-related developments and can advise you on what changes mean for your organization.

CRA Assistant
Questions about Cyber Resilience Act & CRA-Portal
Welcome! I am the CRA Assistant. I can help you with questions about the Cyber Resilience Act, compliance requirements, timelines and how CRA-Portal.eu can support your organization. How can I help you today?