CRA Implementation Enters a Critical Phase
In August 2026, preparations for the implementation of the EU Cyber Resilience Act (CRA) entered a critical stage. With the reporting obligations set to take effect on September 11, 2026, drawing near, the European Commission and the European Union Agency for Cybersecurity (ENISA) have been intensively issuing implementation guidance and materials related to the single reporting platform.
Guidelines on the Application of the Cyber Resilience Act
On July 27, 2026, the European Commission published C(2026) 5252 and its annex, Guidelines on the Application of the Cyber Resilience Act. The guidelines provide explanations of issues of greatest concern to businesses, including scope of application, free and open-source software, substantial modifications, support periods, important and critical products, cybersecurity risk assessments, remote data processing, reporting obligations, and vulnerability handling. They also include 67 practical examples, use cases, and flowcharts to help businesses understand how the CRA should be implemented in practice.
The guidelines themselves are not legally binding, and the Court of Justice of the European Union remains the ultimate authority on interpretation. Nevertheless, they represent the European Commission’s current interpretation of the CRA and therefore provide important practical guidance for manufacturers, market surveillance authorities, and conformity assessment bodies.
Of particular importance to businesses, the guidelines clarify that the reporting obligations under Article 14 of the CRA will apply, from September 11, 2026, to all products with digital elements falling within the scope of the CRA, including products placed on the EU market before December 11, 2027. Furthermore, the reporting obligations do not automatically cease when the product’s support period ends. Following an initial assessment, a manufacturer is deemed to have become aware, thereby triggering the reporting deadlines, once it has reached a reasonable degree of certainty that a vulnerability is being actively exploited or that a severe security incident has occurred.
Single Reporting Platform
On August 3, 2026, ENISA updated the Frequently Asked Questions on the CRA Single Reporting Platform (SRP), the User Registration Guide for Designated Reporting Representatives, and the Guide on Submitting and Updating Notifications. Its dedicated SRP webpage also provides a platform factsheet. On August 14, ENISA further updated the description of the user interface functionalities available to designated reporting representatives. The SRP is intended to provide manufacturers and open-source software stewards with a single electronic entry point, enabling them to submit a notification once to both the relevant coordinating CSIRT and ENISA, after which the coordinating CSIRT will distribute the information to other relevant Member State authorities in accordance with the applicable rules.
As of August 17, 2026, both the European Commission and ENISA state that the SRP will become operational before September 11, 2026. Functional and security testing is still underway, and the dedicated access URL will be announced before the platform officially goes live.
The reporting process follows a phased mechanism. Manufacturers must submit an early warning without undue delay and, in any event, within 24 hours of becoming aware of the issue, followed within 72 hours by general information and a preliminary assessment. For actively exploited vulnerabilities, a final report must be submitted within 14 days after a corrective or mitigating measure becomes available. For severe incidents, a final report must be submitted within one month after the 72-hour notification.
ENISA’s current guidance requires designated reporting representatives to authenticate through EU Login and distinguishes between primary and secondary representatives. Verification by the coordinating CSIRT of the relationship between the representative and the manufacturer may proceed in parallel with the reporting process and does not affect the submission of notifications. ENISA also recommends initiating platform registration and verification only when there is a specific notification to be submitted, rather than conducting large-scale advance registration.
Relevant information
Canada's ISED Officially Releases RSS-310 Issue 6: Major Updates to Radio Frequency Equipment Requirements
Innovation, Science and Economic Development Canada (ISED) has formally issued RSS-310, Issue 6, “Licence-Exempt Radio Apparatus: Category II Equipment,” replacing Issue 5, which has been in effect since 2020
EU Packaging Regulation (PPWR) — Entry into Force on 12 August 2026
On 12 August 2026, the core provisions of the EU Packaging and Packaging Waste Regulation (PPWR, Regulation (EU) 2025/40) became applicable. All packaging placed on the EU market and all related enterprises must comply with the new requirements.