The CRA's first requirement is now in effect. Are you ready?

The CRA's first requirement is now in effect. Are you ready?

On September 11, the first requirements of the EU's Cyber Resilience Act (CRA) will come into effect. For manufacturers of products with digital components, this means that reporting obligations are now a reality.
If an actively exploited vulnerability is discovered in a product, the clock starts ticking. An early warning must be issued within 24 hours of the manufacturer becoming aware of the vulnerability. This requires that the organization not only prepare for CRA, but actually have processes and responsibilities in place when something happens.
What do you need to have in place?
From September onwards you will need:
• ability to detect actively exploited vulnerabilities and incidents that affect the security of your products
• ability to report these to authorities in a short time via ENISA's reporting platform
• ability to quickly develop and distribute security updates
So the question is no longer just whether you have started preparing for CRA. Do the right people know what to do when a vulnerability is discovered? Can you get the information you need? And can you act quickly enough?
New clarifications from the EU
During the summer, the European Commission published new guidance that can make it easier to interpret and implement CRA in the organization.
The guidance clarifies, among other things:
• when remote processing solutions are covered by CRA
• what constitutes a significant change to a product
• how reporting and risk assessment requirements are to be met
For organizations that are still working on interpreting what CRA means for their own products, the guidance can provide answers to several of the questions that arise when the regulations are put into practice.
How far have you come?
ENISA has also published new support during the summer. One of the tools is SME Cyber Resilience Maturity Assessment Model, which together with an Excel template can be used to assess the organization's current maturity level and identify which activities need to be prioritized to strengthen product safety.
ENISA has also published a final version of Security by Design and Default Playbook, which provides more detailed support on how products can be developed in a secure manner.
For the mandatory reporting, ENISA has also published more information on Single Reporting Platform, which should be used to report actively exploited vulnerabilities and incidents that affect product security.
What do you need to focus on until 2027?
The implementation of the reporting obligations is only a first step. Until December 2027, when the CRA becomes fully applicable, affected organizations need to continue developing their processes for, among other things, risk management, vulnerability management and secure product development.
Use the fall to test whether the processes actually work: can you detect, report and manage a vulnerability when it actually happens?
Do you want to delve deeper into CRA?
On September 17, we will be holding a breakfast seminar at Omegapoint where we will go into more depth about what the new requirements mean in practice and how you can plan your work until December 2027.
Read more and register for the breakfast seminar → here
Latest articles






Insights
Latest articles

Digital sovereignty, buzzword or strategic decision?

Whose responsibility is it when AI makes mistakes?
