Articles

Plain-English guides to the regulations and standards we cover — CRA, DORA, NIS2, ISO 27001 and supplier risk.

CRA reporting obligations: what changes on 11 September 2026

From 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents under the CRA. What that requires and how to prepare.

September 7, 2026 · 5 min read

What is the Cyber Resilience Act?

The EU Cyber Resilience Act explained: who it applies to, the essential requirements, and the deadlines that matter — for product and security teams.

September 7, 2026 · 7 min read