logo

EU rules on securing IT products begin this week, but enterprises aren’t ready

ID: 1bed1933-c552-547c-a423-52532db8e223

STIX ID: report--1bed1933-c552-547c-a423-52532db8e223

Feed Name: CIO Security

Date Published: 2026-06-10

Date Updated: 2026-06-10

...
...

The text summarizes the Cyber Resilience Act (CRA) requirements and timelines: conformity assessment bodies designated from June 11, mandatory vulnerability reporting by manufacturers from September 11, and remaining obligations (including fines up to €15 million or 2.5% of global turnover) effective December 11, 2027. It highlights the creation of an open-source steward role to manage software security policies and cites an OpenSSF survey finding that 56% of respondents were unaware of the potential fines, underscoring a gap in organizational preparedness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.