Compliance Pulse

What changed in EU security regulation this week.

A weekly, curated digest of EU regulatory and standards changes that matter to secure software delivery. Short, sourced and dated.

Latest items

Week 41, 2026.

Compliance Pulse · Week 41 · 2026

Now applies11 Sep 2026Cyber Resilience Act · Regulation (EU) 2024/2847

CRA vulnerability and incident reporting obligations now apply

Manufacturers must now notify actively exploited vulnerabilities and severe incidents affecting the security of their products, at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform. An early warning is due within 24 hours and a notification within 72 hours; a final report follows.

Affects Manufacturers of products with digital elements on the EU market, including products placed on the market before 11 December 2027 (Article 69(3)).

Source: Article 14, EUR-Lex →

CRA timeline

  1. Published in the Official Journal
  2. Enters into force
  3. Rules on conformity assessment bodies apply
  4. Reporting obligations apply
  5. Applies in full

Compliance Pulse reports facts about EU acts and guidance. It is not legal advice, and the official text always prevails. Summaries are drafted with AI assistance and reviewed and edited before publication.

What you get

Facts, not advice.

  1. One digest a weekThe Cyber Resilience Act, DORA, NIS2 and the AI Act, plus guidance from ENISA, the European Supervisory Authorities and the European standards bodies.
  2. What changed, and whenEach item states the change, its legislative stage, who it affects and from which date.
  3. Primary sources onlyEvery item links to the official text. Where a summary and the source differ, the source prevails.

Corrections and questions.

Spotted an error or a change we missed? Write to us. Corrections are shown on the item, with a date.