From 11 September 2026, manufacturers of software, IoT products and other products with digital elements will become subject to the first obligations introduced by the Cyber Resilience Act (CRA). From that date, they will have 24 hours to submit an early warning and 72 hours to submit a complete notification of an actively exploited vulnerability […]
Frauscher earns IEC 62443-4-1 certification for its Secure Development Lifecycle, boosting rail cyber security.
EU's Cyber Resilience Act brings strict incident reporting by Sept 2026. Learn key deadlines, risk c
Understand the EU Cyber Resilience Act and determine if your product falls within its scope. Learn about definitions, classifications and compliance obligations
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) (the “CRA”) entered into force on 10 December 2024 and will apply in full from 11 December 2027. On 27 July...
As software supply chain risks grow and EU Cyber Resilience Act obligations approach, the partnership brings binary-level software verification to enterprises and public sector organizations across the...
The EU Cyber Resilience Act introduces new cybersecurity requirements for digital products and services across the European Union. Understanding the recently published guidance is crucial for businesses...
A cybersecurity historian argues the EU Cyber Resilience Act overreaches through unworkable mandates, sprawling jurisdiction and outdated assumptions, urging a streamlined successor that embraces AI, existing standards and practical enforcement instead of bureaucratic complexity today.
The European Commission has published its final guidance on the application of the EU Cyber Resilience Act (
The list of everyday devices compromised by cyberattackers seems to grow longer every day, from fish tanks to toasters , baby monitors to...
The European Commission has published guidance on the Cyber Resilience Act, weeks before its mandatory 24-hour vulnerability and incident reporting obligations begin to apply.
EU Cyber Resilience Act: 24-Hour Reporting Duties Start September 11, 2026
Final reports must follow within 14 days after a corrective or mitigating measure becomes available for an actively exploited vulnerability or within one month of the 72-hour incident notification
Strategic collaboration will unite two global open source communities to advance security practices, support maintainers and stewards, and help organisations prepare for the EU Cyber Resilience Act
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
ENISA is the EU agency dedicated to enhancing cybersecurity in Europe. They offer guidance, tools, and resources to safeguard citizens and businesses from cyber threats.
CRA: Security must be built into architecture, hardware, and software from day one – especially for embedded and IoT development.
On 27 July, the European Commission published a practical guide to the Cyber Resilience Act, the EU’s legislation on cyber resilience. The document contains
Manufacturers, developers and businesses of all sizes across the EU now have new guidance on how to apply the Cyber Resilience Act. This will help them prepare for mandatory cybersecurity requirements and reporting obligations. The new Commission guidance explains how these rules apply in practice. It clarifies which products fall within the scope of the Act, what […]
Learn how Nord Security contributes expertise through ETSI to standards supporting the EU Cyber Resilience Act.
The European Commission published final guidance for complying with the Cyber Resilience Act, a 2024 law that aims to boost the cybersecurity of software and
The Commission's Cyber Resilience Act guidance helps manufacturers and developers prepare for mandatory cybersecurity requirements.
The EU has published guidance to help manufacturers, developers, and businesses meet obligations under the EU's Cyber Resilience Act.
The EU has published guidance to help manufacturers, developers, and businesses meet obligations under the EU's Cyber Resilience Act.
The European Commission has published guidance for manufacturers and regulators implementing the Cyber Resilience Act, the EU's law on mandatory cybersecurity for digital devices and related services. In effect since December 2024, the law lays out the requirements for obtaining the CE mark for safe products. The guidelines come ahead of new CRA obligations taking effect this September to report and patch security vulnerabilities discovered in digital products. From December 2027 the remaining obligations t



















