started · updated
Czech Chamber of Commerce warns of upcoming Cyber Resilience Act obligations
The Czech Chamber of Commerce has issued a warning to companies regarding new obligations under the European Cyber Resilience Act (CRA). While most provisions of the regulation will not be fully applicable until December 2027, certain requirements for hardware and software manufacturers will take effect as early as September 11, 2026.
Under Article 14 of the CRA, companies will be required to actively report exploited vulnerabilities and serious security incidents. Manufacturers must submit a preliminary report via a unified European platform managed by ENISA within 24 hours of becoming aware of a relevant issue. This must be followed by a more detailed report within 72 hours.
The European Commission recently released new guidelines to clarify the practical application of the CRA, covering digital products, cloud services, and remote services, as well as risk assessment and conformity assessment methods for high-risk products.
Entities
Cyber Resilience Act · Czech Chamber of Commerce · ENISA · European Commission