Kyberkestävyyssäädöksen vaatimukset selkiytyvät - EU-komissio julkaisi uuden soveltamisohjeen

www.kyberturvallisuuskeskus.fi/fi/uutise…

The European Commission has published new guidance to help manufacturers, software developers, and other companies placing digital products on the market prepare for the Cyber Resilience Act (CRA). The non-binding guidance clarifies product scope, supply-chain responsibilities, and the cybersecurity requirements that apply across a product’s full lifecycle.

Practical examples are included to help micro and small enterprises assess the regulation’s impact. The first obligations—vulnerability and incident reporting—take effect on 11 September 2026, with the core cybersecurity requirements applying to manufacturers from 11 December 2027.

Edward Kiledjian @ekiledjian