The EU Cyber Resilience Act (CRA) will impose cybersecurity requirements on hardware, software, and components sold in the EU, with broad applicability including commercially supplied offline firmware from microenterprises. Manufacturers will need to maintain technical documentation, issue an EU declaration of conformity, apply CE marking where required, provide security updates throughout the support period, and meet post-market vulnerability and incident-reporting obligations; some software not listed in Annex III may be eligible for self-assessment.
The Netherlands has proposed an implementing law that assigns conformity assessment, market surveillance, and enforcement to the Minister of Economic Affairs through the Rijksinspectie Digitale Infrastructuur (RDI). The National Cyber Security Centre (NCSC) would operate the national reporting portal as the designated CSIRT. CRA market requirements take effect on 11 December 2027, while manufacturers must begin reporting actively exploited vulnerabilities and severe incidents on 11 September 2026.

See the reporting duties and controls this puts on the clock.
5 events from the most recent confirmed update back to the earliest known activity.
The European Commission issued guidance C(2026) 5252 addressing CRA obligations, including that vulnerability handling ends with the support period while reporting obligations continue afterward.
The Netherlands opened a public consultation on a draft law to implement the EU Cyber Resilience Act operationally, including proposed designation of the RDI for oversight and market surveillance and the NCSC as the reporting-portal CSIRT.
The European Union adopted the Cyber Resilience Act as Regulation (EU) 2024/2847, establishing cybersecurity requirements for products with digital elements.
The Digital Trust Center was integrated into the Netherlands' National Cyber Security Centre.
The Dutch Ministry of Economic Affairs held an online information session covering the draft CRA implementing law and the Cyber Resilience Act.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
blog.compass-security.com
Open sourcenews.ycombinator.com
Open sourcencsc.nl
Open sourceeur-lex.europa.eu
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.