< Back to all clusters
[TECHNOLOGY] · Germany, EU · 3 sources

started · updated

EU Cyber Resilience Act introduces new digital product security mandates

The European Union's Cyber Resilience Act (CRA) is introducing mandatory cybersecurity requirements for products with digital elements. Starting September 11, 2026, manufacturers must report actively exploited vulnerabilities and serious security incidents. The regulation will be fully applicable by December 11, 2027.

Products covered include hardware and software that connect to a device or network, whether through a public internet connection or not. Requirements span the entire product lifecycle, including secure development, vulnerability management, and the maintenance of a Software Bill of Materials (SBOM).

To assist with this transition, Germany's Federal Office for Information Security (BSI) has released technical guideline TR-03183. While not a mandatory standard or a guarantee of compliance, the guide serves as a practical starting point for manufacturers to establish IT security processes. The guideline covers general requirements, SBOM documentation—including formats like SPDX and CycloneDX—and vulnerability management. It is intended to be gradually replaced by harmonized European standards as they become available.

Entities

Federal Office for Information Security