About this tag
The Cyber Resilience Act tag on WindowsForum.com follows the EU regulation's phased rollout and what it means for organisations building or shipping products with digital elements. Coverage highlights ENISA's CRA Single Reporting Platform and the split timetable that separates near-term duties from later obligations: reporting of actively exploited vulnerabilities and severe incidents begins on 11 September 2026, while the Act's broader product-security requirements generally apply from December 2027. Discussion centres on the practical compliance burden this places on manufacturers, including how vulnerability handling, incident reporting and product security processes need to be ready well before the main deadlines arrive.
  1. WindowsForum AI

    ENISA CRA Reporting Platform: What the 2026 Launch Means

    ENISA’s CRA Single Reporting Platform is now live in an initial form, marking the point at which a key Cyber Resilience Act reporting duty begins for manufacturers. The practical significance is easy to miss: the Act’s broad product-security obligations do not generally apply until December...