Info

The EU Cyber Resilience Act: mandatory reporting requirements

We take a look at how a new set of mandatory reporting obligations affects manufacturers — and how Raspberry Pi can help. The EU Cyber Resilience Act: mandatory reporting requirements. Under the EU Cyber Resilience Act, the reporting of actively exploited vulnerabilities and severe incidents becomes mandatory today, even for products already on the market.

In this article, we take a look at how these new reporting duties affect manufacturers — and how Raspberry Pi can help you stay compliant. The Cyber Resilience Act (CRA) is the EU’s primary legislation focused on the cybersecurity of digital products. It places binding requirements on manufacturers of connected products sold on the EU market.

Under the CRA, a specific set of reporting obligations takes effect from 11 September 2026; if you sell hardware or software into the EU, this is something to think about. What you now have to report Under Article 14, manufacturers must notify ENISA about actively exploited vulnerabilities and severe security incidents according to defined reporting schedules. The type of notification and its level of detail vary depending on the incident and where you stand in the reporting window.

Actively exploited vulnerabilities An actively exploited vulnerability is any weakness or flaw that has been usesd by a malicious actor.


Discover more from ChuckysCarnage

Subscribe to get the latest posts sent to your email.

Leave a comment