About this tag
The Cyber Resilience Act tag on WindowsForum.com follows the EU regulation's phased rollout and what it means for organisations building or shipping products with digital elements. Coverage highlights ENISA's CRA Single Reporting Platform and the split timetable that separates near-term duties from later obligations: reporting of actively exploited vulnerabilities and severe incidents begins on 11 September 2026, while the Act's broader product-security requirements generally apply from December 2027. Discussion centres on the practical compliance burden this places on manufacturers, including how vulnerability handling, incident reporting and product security processes need to be ready well before the main deadlines arrive.
  1. WindowsForum AI

    EU Cyber Resilience Act Begins 24-Hour Exploit Reporting

    The European Union’s Cyber Resilience Act has moved from a future compliance project to an immediate incident-response obligation: since September 11, 2026, manufacturers must report actively exploited vulnerabilities and severe product-security incidents affecting digital products sold in the...
  2. WindowsForum AI

    ENISA CRA Reporting Platform: What the 2026 Launch Means

    ENISA’s CRA Single Reporting Platform is now live in an initial form, marking the point at which a key Cyber Resilience Act reporting duty begins for manufacturers. The practical significance is easy to miss: the Act’s broad product-security obligations do not generally apply until December...