Независимо ръководство за Регламент (ЕС) 2024/2847 · Състояние: в сила
Тази страница е автоматичен превод (с ИИ) и не е прегледана от човек. Статиите в блога са достъпни само на английски език.
Последни новини · Блог

Новини и анализи за CRA

Анализ, регулаторни актуализации и оценки CRA Fast Check; за производители, разработчици на софтуер, вносители и дистрибутори.

Бърза проверка
23 July 2026

Fast Check: After CISA's 14 July 2026 SonicWall Warning, SMA 1000 VPN Appliances Fall Under the CRA's Class I Rules

On 14 July 2026, CISA flagged two actively exploited SonicWall SMA 1000 zero-days. Under the CRA, a VPN appliance is an Annex III Class I important product…

Прочетете статията →
Fast Check: After CISA's 14 July 2026 SonicWall Warning, SMA 1000 VPN Appliances Fall Under the CRA's Class I Rules
Още от блога

Скорошни публикации

Бърза проверка
20 July 2026

Fast Check: After a 14 July 2026 Root Exploit Disclosure, the Lorex 2K Wi-Fi Camera Falls Under CRA Class I

On 14 July 2026, researchers disclosed an unauthenticated root exploit in the Lorex 2K Wi-Fi camera, a device the CRA treats as a Class I important product…

Четене →
CRA Insights
16 July 2026

On 13 July 2026, ENISA Published a Free Maturity Model So SMEs Can Score Their CRA Readiness

On 13 July 2026, ENISA released a free self-assessment tool scoring SMEs across five CRA-relevant domains, from governance to vulnerability handling…

Четене →
Бърза проверка
13 July 2026

Fast Check: After CERT/CC's 6 July 2026 Tenda Backdoor Warning, Home Routers Fall Under the CRA's Class I Rules

CERT/CC's 6 July 2026 warning revealed a hidden admin backdoor in Tenda routers, and the vendor is not responding. Under the CRA, routers are Annex III Class I products…

Четене →
Бърза проверка
6 July 2026

Fast Check: After CISA's 3 July 2026 Fortinet Warning, FortiGate Firewalls Fall Under the CRA's Class II Rules

CISA flagged actively exploited Fortinet flaws on 3 July 2026. Under the CRA, a firewall like FortiGate is an Annex III Class II product, the tier that cannot self-assess…

Четене →
CRA Insights
2 July 2026

On 24 June 2026, ENISA's First SME Survey Found High CRA Awareness but Low Readiness

ENISA's first SME survey, published on 24 June 2026, found high awareness of the CRA but thin practical readiness, with incident response and SBOM the weakest areas…

Четене →
CRA Insights
29 June 2026

With Reporting Due on 11 September 2026, ENISA's Single Reporting Platform Is Still Not Live

Mandatory vulnerability reporting starts on 11 September 2026, yet the one tool manufacturers must use to file those reports is not operational yet…

Четене →
CRA Insights
26 June 2026

On 11 June 2026, the CRA's Rules on Notified Bodies Started to Apply, but None Are Designated Yet

On 11 June 2026, Chapter IV of the CRA switched on the rules for notified bodies, the third-party assessors some products will need, yet none have been designated…

Четене →
CRA Insights
26 June 2026

A Newly Adopted Delegated Act Lets Authorities Hit Pause on Vulnerability Disclosure

On 11 December 2025 the Commission set out when an authority can delay sharing a reported vulnerability, even as the 24-hour reporting clock starts on 11 September 2026…

Четене →
CRA Insights
30 March 2026

One Product, Two Worlds: Will the EU’s Cyber Resilience Act Trigger a US Ban?

For global tech manufacturers, the "Holy Grail" is a single product design that can be sold everywhere. But a regulatory…

Четене →
CRA Insights
26 March 2026

The Router Revolution: Why the FCC Ban is a Global Game Changer

By Erel Rosenberg, Clea Rozenblum and SeongEun Kim i46 s.r.o. - For years, the conversation around router security was about…

Четене →
CRA Insights
7 January 2026

Why Risk Assessment Falls Short in Cybersecurity

While new regulations like the Cyber Resilience Act (CRA) and the AI Act make risk assessment a legal requirement, they often put manufacturers in a…

Четене →
CRA Insights
18 December 2025

Understanding the Notepad++ Updater Hijack

The Notepad++ Updater Hijack refers to a security vulnerability, specifically a DLL Hijacking attack, that was discovered and exploited in the update…

Четене →
CRA Insights
29 October 2025

DISK46: A Secure, LUKS-Preinstalled Linux Distribution for Raspberry Pi Risk Assessment

I. Product Identification DISK46 represents a specialized Linux distribution image, meticulously crafted with a…

Четене →
CRA Insights
23 October 2025

Securing the Edge: Disk Encryption Challenges Under the EU CRA

The European Union's Cyber Resilience Act (CRA) is redefining security mandates for all products with digital elements. For IoT device…

Четене →
Бърза проверка
14 June 2024

IP-Time N608

is a router manufactured by IP-Time/EFM since 2010. The device does not comply with the CRA.

Четене →
Бърза проверка
14 June 2024

Huawei B311 Home Router

IP-Time N608 is a router manufactured by IP-Time/EFM since 2010. The device does not comply with the CRA.

Четене →
Бърза проверка
14 June 2024

SpeedPort LTE II

SpeedPort is a router manufactured by Huawei since at least 2013. The device does not comply with the CRA.

Четене →
Бърза проверка
13 June 2024

IP-Time A3004NS-M

is a router manufactured by EFM in 2019. This is an old device, which does not need to conform with the CRA. However, if it had to, its current setup is found not compliant with the requirements of the CRA.

Четене →
Бърза проверка
13 June 2024

TP-Link Archer AX73 V2

is a router manufactured by TP Link. While the device is reasonably secured, it does not comply with the CRA.

Четене →
Posts are imported from the cyberresilienceact.eu blog. 20 статии в 2 categories.