24 hours to report a vulnerability. What does Article 14 of the Cyber Resilience Act mean in practice?

From 11 September 2026, manufacturers of software, IoT products and other products with digital elements will become subject to the first obligations introduced by the Cyber Resilience Act (CRA). From that date, they will have 24 hours to submit an early warning and 72 hours to submit a complete notification of an actively exploited vulnerability […]

Building Cyber Resilience Into Rail

Frauscher earns IEC 62443-4-1 certification for its Secure Development Lifecycle, boosting rail cyber security.

Brussels Unveils 80-Page Playbook as EU Cyber Rules Tighten for Connected Products

EU's Cyber Resilience Act brings strict incident reporting by Sept 2026. Learn key deadlines, risk c

Does the EU Cyber Resilience Act apply to your product? Scope, definitions and the product classification system explained

Understand the EU Cyber Resilience Act and determine if your product falls within its scope. Learn about definitions, classifications and compliance obligations

Does the EU Cyber Resilience Act apply to your product? Scope, definitions and the product classification system explained

The EU Cyber Resilience Act (Regulation (EU) 2024/2847) (the “CRA”) entered into force on 10 December 2024 and will apply in full from 11 December 2027. On 27 July...

Insignary and Barrier Networks Partner to Bring Binary-Level Software Supply Chain Security to UK Enterprises and Public Sector

As software supply chain risks grow and EU Cyber Resilience Act obligations approach, the partnership brings binary-level software verification to enterprises and public sector organizations across the...

EU Cyber Resilience Act Guidance Now Out: Here's What You Need To Know

The EU Cyber Resilience Act introduces new cybersecurity requirements for digital products and services across the European Union. Understanding the recently published guidance is crucial for businesses...

The EU Cyber Resilience Act Regime: A Failure to Know Your Limitations

A cybersecurity historian argues the EU Cyber Resilience Act overreaches through unworkable mandates, sprawling jurisdiction and outdated assumptions, urging a streamlined successor that embraces AI, existing standards and practical enforcement instead of bureaucratic complexity today.

eu-cyber-resilience-act-european-commission-publishes-final-cra-guidance

The European Commission has published its final guidance on the application of the EU Cyber Resilience Act (

EU Cyber Resilience Act guidance now out: here's what you need to know

The list of everyday devices compromised by cyberattackers seems to grow longer every day, from fish tanks to toasters , baby monitors to...

EU Cyber Resilience Act: 24-Hour Reporting Duties Start September 11, 2026

The European Commission has published guidance on the Cyber Resilience Act, weeks before its mandatory 24-hour vulnerability and incident reporting obligations begin to apply.

EU Cyber Resilience Act: 24-Hour Reporting Duties Start September 11, 2026

EU Cyber Resilience Act: 24-Hour Reporting Duties Start September 11, 2026

Manufacturers face 24-hour EU cyber reporting deadline from September

Final reports must follow within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability or within one month of the 72-hour incident notification

Eclipse Foundation and OWASP Join Forces to Strengthen Open Source Security and CRA Readiness

Strategic collaboration will unite two global open source communities to advance security practices, support maintainers and stewards, and help organisations prepare for the EU Cyber Resilience Act

Product Security

ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.

Where do SMEs stand in preparing for the Cyber Resilience Act?

ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.

Cyber Resilience Act, Part 2: Security by Design becomes mandatory

CRA: Security must be built into architecture, hardware, and software from day one – especially for embedded and IoT development.

The EU explains the Cyber Resilience Act. Companies have a few weeks to prepare

On 27 July, the European Commission published a practical guide to the Cyber Resilience Act, the EU’s legislation on cyber resilience. The document contains

Commission publishes new guidance to support businesses' implementation of the Cyber Resilience Act

Manufacturers, developers and businesses of all sizes across the EU now have new guidance on how to apply the Cyber Resilience Act. This will help them prepare for mandatory cybersecurity requirements and reporting obligations. The new Commission guidance explains how these rules apply in practice. It clarifies which products fall within the scope of the Act, what […]

Nord Security has joined ETSI to help shape CRA standards

Learn how Nord Security contributes expertise through ETSI to standards supporting the EU Cyber Resilience Act.

IoT Sector Given Final EU Cyber Resilience Act Guidance

The European Commission published final guidance for complying with the Cyber Resilience Act, a 2024 law that aims to boost the cybersecurity of software and

EU publishes Cyber Resilience Act guidance for businesses

The Commission's Cyber Resilience Act guidance helps manufacturers and developers prepare for mandatory cybersecurity requirements.

Brussels issues guidance to support businesses' implementation of EU Cyber Resilience Act - EUbusiness.com | EU news, business and politics

The EU has published guidance to help manufacturers, developers, and businesses meet obligations under the EU's Cyber Resilience Act.

Brussels issues guidance to support businesses' implementation of EU Cyber Resilience Act - EUbusiness.com | EU news, business and politics

The EU has published guidance to help manufacturers, developers, and businesses meet obligations under the EU's Cyber Resilience Act.

EU publishes guidance on new cybersecurity rules for connected devices

The European Commission has published guidance for manufacturers and regulators implementing the Cyber Resilience Act, the EU's law on mandatory cybersecurity for digital devices and related services. In effect since December 2024, the law lays out the requirements for obtaining the CE mark for safe products. The guidelines come ahead of new CRA obligations taking effect this September to report and patch security vulnerabilities discovered in digital products. From December 2027 the remaining obligations t