|
|
Reporting obligations: 2026-09-11
|
CRA Watch
Monthly CRA briefing, verified against official sources · Issue 1 · 2026-08-14
|
| |
|
Ahead of the 11 September start date, Europe moved fast. This issue covers only what we verified against official
sources between late July and 14 August 2026 — SRP operational guidance, the final EC
guidance, standardisation deadlines, and one interpretation that keeps going wrong.
|
|
24 hours
Early warning
|
72 hours
Notification
|
Final report
after fix · 1 month (incidents)
|
From 11 September, these clocks start the moment you become aware — and the reporting platform (ENISA SRP) runs in English.
|
| This issue's lead |
TOP STORY |
SRP operational guidance is out — reporting practice is taking shape
ENISA published a factsheet plus registration and notification-submission guides for Assigned
Representatives (AR) on its Single Reporting Platform pages, updated as of 3 August. The 24h/72h/final
reports that existed only on paper now have concrete screen-level procedures.
| – | Reporting accounts require an EU Login created in advance — the Primary AR links the manufacturer; Secondary ARs join by email invitation (expires in 7 days) |
| – | Early warning → 72-hour → final report tab structure · drafts can be saved · no editing after final submission |
| – | No API at launch (FAQ Q15) — the working assumption is a person typing into the portal |
| – | A webinar is promised two weeks before go-live (expect late August) · voluntary reporting activates after 11 September |
→ What this means: registering "after go-live" on 11 September is too late. Decide now who your AR is and whose EU Login it will be.
Source: ENISA SRP pages · 2 AR guides (updated 2026-08-03, re-checked 14 Aug)
|
📘 EC publishes final CRA application guidance — 67 examples, 84 pages 27 Jul
"Becoming aware" = a reasonable degree of certainty after an initial assessment (guidance paragraphs 212–213) ·
no retroactive reporting for exploitation known before 11 September · component vulnerabilities are reportable
only where exploitable/reachable in your own product · the 5-year support period is not a default (paragraph 126).
→ You now have official grounds to document your internal "moment of awareness" criteria.
🛡️ ENISA scales up its role in the CVE Program 6 Aug
NATO's NCIA and AISLE joined as CNAs under the ENISA Root — now 20 in total. The agency that runs the
EU Vulnerability Database (EUVD) and the SRP is extending into vulnerability identification infrastructure.
→ Expect more Europe-issued CVEs — monitoring the US NVD alone is getting narrower.
🗳️ Public consultation on the EUMSS certification scheme 24 Jul – 13 Sep
A candidate certification scheme for EU Managed Security Services, on the same CSA track as EUCC —
a horizontal base layer plus service profiles. Comments via EU Survey until 13 September.
→ If you outsource security operations, vendor selection criteria are starting to converge on EU certification.
📊 ENISA releases an SME CRA maturity self-assessment 13 Jul
A free Excel tool scoring five domains on a 1–5 scale. The accompanying survey of 194 organisations
shows where the market stands:
| CRA awareness |
|
66% |
| Readiness |
Low — incident response and product lifecycle management are the weakest areas |
→ Benchmark yourself with the free self-assessment — but note a maturity score is not conformity (Article 32 assessment is separate).
|
| Harmonised standards cited in the OJ |
🔴 0 |
Annex I direct assessment remains the premise |
| Notified Bodies listed |
🔴 0 |
"Sufficient number" targeted by 11 Dec |
| M/606 amendment |
🟡 not adopted |
Current deadlines stand (earliest 30 Aug) |
| Horizontal security requirements (prEN 40000-1-4) |
🟡 delayed |
Public enquiry pushed to Oct–Nov |
→ Harmonised standards are still pending, but the substance of the obligations (Annex I) is already fixed — risk assessment, vulnerability handling and documentation can mostly be prepared today.
|
| Worth clearing up |
FACT CHECK |
"CRA compliance also settles the Machinery Regulation's cyber requirements"?
|
✖ The misconception — a CRA Declaration of Conformity creates a presumption of
conformity with the Machinery Regulation's cybersecurity requirements (Annex III §1.1.9 · §1.2.1).
✔ What the texts say — the presumption comes from certification under a
Cybersecurity Act (CSA) scheme (Machinery Regulation Art 20(9)). CRA compliance "could facilitate"
those requirements, and the synergies must be demonstrated by the manufacturer (CRA Recital 53).
Both regulations must be met, with a single consolidated EU Declaration of Conformity (Art 21(3)).
Source: EUR-Lex CELEX 32023R1230 Art 20(9)·21(3) / 32024R2847 Recital 53 — verified against the originals 2026-08-08
|
|
|
The next issue follows next month — if nothing changed, we won't send. If you found this briefing useful, forward it to a colleague.
|
|
Get this briefing by email
Monthly · free · no tracking pixels — if nothing changed, we won't send.
Subscribe to CRA Watch →
|
|
|
CRA Watch is published by ACE LABS Co., Ltd. — an independent advisory firm supporting Korean manufacturers with CRA compliance.
|
|
This page is the web edition of CRA Watch, our email briefing.
This newsletter is provided for general information and is not legal advice.
Its content is verified against official sources (EUR-Lex · EC · ENISA · CEN official DB) as of the publication date.
ACE LABS Co., Ltd. · CEO Minseok Ro · Business reg. no. 273-81-03550
17, Gukjegeumyung-ro 2-gil, Yeongdeungpo-gu, Seoul (Citiplaza #444) · ceo@acelabs.co.kr · www.acelabs.co.kr
© 2026 ACE LABS. All rights reserved.
|