[REVISION HISTORY]
EU Cyber Resilience Act compliance and reporting
Updated 3 times since CLSTR started tracking revisions of this situation.
What changed
2026-08-12 09:30 UTC → 2026-08-17 23:35 UTC ·
added
removed
The EU Cyber Resilience Act (CRA) imposes mandatory security-by-design, secure over-the-air updates, and lifecycle management obligations on most connected devices sold in the EU. While full CRA requirements become binding on 11 December 2027, specific reporting obligations for actively exploited vulnerabilities and serious security incidents are set to begin on 11 September 2026. These upcoming reports must be submitted to the European Union Agency for Cybersecurity (ENISA) through a single reporting platform. National Computer Security Incident Response Teams (CSIRTs), such as Germany’s BSI, will coordinate responses at the national level. Additionally, ENISA is mandated to maintain an EU Vulnerability Database to assist manufacturers in cross-referencing their software bills of materials (SBOMs). To assist manufacturers and SMEs, support implementation, the European Commission has issued practical, approved an 83-page non-binding guidance. guidance document on 27 July 2026. This documentation includes guide, containing 67 worked examples and five flowcharts, examples, assists market-surveillance authorities and use-case diagrams to help interpret notified bodies in interpreting the regulation. It clarifies the scope of the CRA, define substantial modifications, products with digital elements, distinguishing between software installed on devices, web-based applications, and outline risk-assessment procedures. German SMEs continue source-code licences. For instance, it notes that a downloadable game client falls within scope, whereas a browser-only game does not. In parallel, the European Telecommunications Standards Institute (ETSI) has moved 17 cybersecurity standards into the formal approval process. These standards aim to face tight deadlines translate CRA legal obligations into technical requirements for categories including network and limited state aid, relying on edge devices, IoT appliances, and security software. They cover baseline requirements such as modern encryption, secure default configurations, and the EU SECURE programme to build necessary use of machine-readable software bills of materials (SBOM). As the September 2026 deadline for vulnerability reporting approaches, manufacturers are advised to review internal processes. The regulatory landscape is further influenced by similar proposals, such as Under the United Kingdom’s Cyber Security and Resilience Bill, as CRA, companies must submit an early warning for actively exploited vulnerabilities within 24 hours to the market moves toward stricter IoT and edge-device security standards. European Union Agency for Cybersecurity (ENISA) via a single reporting platform.
Versions
- 2026-08-17 23:35 UTC EU Cyber Resilience Act compliance and reporting
- 2026-08-12 09:30 UTC EU Cyber Resilience Act compliance and reporting
- 2026-08-05 05:53 UTC EU Cyber Resilience Act compliance
- 2026-07-28 09:02 UTC EU Cyber Resilience Act compliance
Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.