EU Cyber Resilience Act reporting rules now in effect
Product makers covered by the EU Cyber Resilience Act (CRA) must now report actively exploited vulnerabilities and major security incidents via the EU’s reporting process, taking effect from September 11. Broader requirements of the CRA are due to come into force in December 2027. The shift means organizations must show detailed traceability and controls within their software development and release processes, rather than addressing compliance late in the cycle.
- CRA vulnerability reporting started September 11
- All digital product makers in scope must comply
- Traceability in code and release pipelines required
- Full CRA obligations begin in December 2027
Sources covering this
More in Cybersecurity
Pentagon data breach exposes records of over 3 million people
Hackers accessed the Defense Manpower Data Center’s database over nine months, exposing sensitive records of about 2.76 million living…
Cisco SD-WAN Manager vulnerability actively exploited
Cisco has disclosed a critical security vulnerability (CVE-2026-76504) in Catalyst SD-WAN Manager that is being exploited by attackers.
Cisco Talos highlights defender tactics for Cybersecurity Month
Cisco Talos is marking Cybersecurity Awareness Month by sharing practical tips for defenders to frustrate attackers at every stage.
AI accelerates discovery of high-risk software vulnerabilities
Google’s Threat Intelligence Group reported that monthly vulnerability disclosures have doubled this year, increasing from 5,045 in…