The Cyber Resilience Act (CRA), a new European regulation (UE 2024/2847) aimed at improving the cybersecurity of digital products, is entering a new phase on September 11. Starting on this date, manufacturers will be required to report any actively exploited vulnerabilities or serious security incidents affecting their products to ENISA, the European Union's central cybersecurity agency. The CRA officially took effect on December 10, 2024, and applies directly to all EU member states without needing to be rewritten into national laws. Full implementation is expected by December 2027, and it will affect any organization that sells a product with at least one digital component.
The CRA categorizes products into three levels of risk. "Common" products, which are considered low risk, can be self-assessed by manufacturers. "Important" products, listed in Annex III, include items like identity management systems, web browsers, password managers, antivirus software, and virtual private networks (VPNs). These require evaluation by a dedicated organization. "Critical" products, listed in Annex IV, such as hardware with security modules, smart meter gateways, and chip card systems, also require evaluation by a dedicated organization due to their high risk to security.
Starting on September 11, 2026, Article 14 of the CRA will require manufacturers of digital products to report two types of events: vulnerabilities that are actively being exploited and serious incidents that affect product security. Manufacturers must inform ENISA within 24 hours of discovery (referred to as "early" notification), provide a full report within 72 hours, and submit a final comprehensive report within 14 days. These deadlines are aligned with those set by the NIS2 directive, aiming to create a unified cybersecurity framework across the EU.
ENISA will act as the central point of contact for these reports. The agency will distribute the information to each member country's Computer Security Incident Response Team (CSIRT). In France, this is known as CERT-FR. The French National Cybersecurity Agency (ANSSI) will then receive, analyze, and coordinate the handling of the information. If the product is sold in other countries, CERT-FR will also share the information with its international counterparts to ensure a coordinated response.
Although the full implementation of the CRA will have significant long-term impacts, the requirement to report vulnerabilities and incidents by September 11 is equally important. This obligation applies to a wide range of companies and is retroactive, meaning it applies to all products currently on the market. This is different from other European regulations, such as the requirement for smartphones to receive at least five years of software updates, which only apply to future products.
Cyber Resilience Act Enters New Phase with Reporting Obligations
AI-rewritten from original reportingHow it works
cracybersecurityenisaeu-regulationvulnerability-reportingcisrt
Original sources:
- 🇫🇷Next
- 🇫🇷ZDNet France



