Sõltumatu juhend määruse (EL) 2024/2847 kohta · Staatus: jõustunud
See leht on automaatne (tehisintellekti) tõlge ja seda ei ole inimene üle vaadanud. Blogiartiklid on saadaval ainult inglise keeles.
Veel blogist

Hiljutised postitused

CRA ülevaated
13 August 2026

ENISA's 3 August 2026 Update Says CSIRT Validation Is Not a Precondition for Reporting, and Cross-Border Sharing Is a Manual Step

ENISA re-dated its Single Reporting Platform guidance to 3 August 2026 and changed two things quietly. Both affect how manufacturers should prepare for 11 September…

Loe →
CRA ülevaated
10 August 2026

On 6 August 2026, ENISA Announced Its CVE Root Now Covers 20 Numbering Authorities, Five Weeks Before CRA Reporting Starts

ENISA's 6 August 2026 announcement puts 20 CVE Numbering Authorities under its Root. It matters for the CRA, because a CVE record is not an Article 14 notification…

Loe →
CRA ülevaated
6. august 2026

ENISA Published Step-by-Step Single Reporting Platform Instructions on 31 July 2026, Five Weeks Before Reporting Starts

ENISA's Single Reporting Platform guidance, updated 31 July 2026, now shows the actual registration and notification screens. The URL is still unpublished…

Loe →
Kiirkontroll
3 August 2026

Fast Check: After CISA's 30 July 2026 WireGuard Key Advisory, MikroTik's RouterOS Falls Under the CRA's Class I Rules

CISA's 30 July 2026 advisory says a low-privilege RouterOS API session can read a MikroTik router's WireGuard private key in plaintext, and there is no patch…

Loe →
CRA ülevaated
30 July 2026

The Commission's Draft Amendment Pushes the CRA's 2026 Harmonised-Standard Deadlines Back by Two Months

In early July 2026, the Commission proposed pushing the CRA's 2026 harmonised-standard deadlines back two months, and no standard is yet cited in the Official Journal…

Loe →
CRA ülevaated
27 July 2026

On 27 July 2026, the Commission Published Its First Official Guidance on Applying the Cyber Resilience Act

On 27 July 2026, the Commission published official guidance on applying the CRA, clarifying scope, substantial modification, support periods and reporting for SMEs…

Loe →
Kiirkontroll
23 July 2026

Fast Check: After CISA's 14 July 2026 SonicWall Warning, SMA 1000 VPN Appliances Fall Under the CRA's Class I Rules

On 14 July 2026, CISA flagged two actively exploited SonicWall SMA 1000 zero-days. Under the CRA, a VPN appliance is an Annex III Class I important product…

Loe →
Kiirkontroll
20 July 2026

Fast Check: After a 14 July 2026 Root Exploit Disclosure, the Lorex 2K Wi-Fi Camera Falls Under CRA Class I

On 14 July 2026, researchers disclosed an unauthenticated root exploit in the Lorex 2K Wi-Fi camera, a device the CRA treats as a Class I important product…

Loe →
CRA ülevaated
16 July 2026

On 13 July 2026, ENISA Published a Free Maturity Model So SMEs Can Score Their CRA Readiness

On 13 July 2026, ENISA released a free self-assessment tool scoring SMEs across five CRA-relevant domains, from governance to vulnerability handling…

Loe →
Kiirkontroll
13 July 2026

Fast Check: After CERT/CC's 6 July 2026 Tenda Backdoor Warning, Home Routers Fall Under the CRA's Class I Rules

CERT/CC's 6 July 2026 warning revealed a hidden admin backdoor in Tenda routers, and the vendor is not responding. Under the CRA, routers are Annex III Class I products…

Loe →
Kiirkontroll
6 July 2026

Fast Check: After CISA's 3 July 2026 Fortinet Warning, FortiGate Firewalls Fall Under the CRA's Class II Rules

CISA flagged actively exploited Fortinet flaws on 3 July 2026. Under the CRA, a firewall like FortiGate is an Annex III Class II product, the tier that cannot self-assess…

Loe →
CRA ülevaated
2 July 2026

On 24 June 2026, ENISA's First SME Survey Found High CRA Awareness but Low Readiness

ENISA's first SME survey, published on 24 June 2026, found high awareness of the CRA but thin practical readiness, with incident response and SBOM the weakest areas…

Loe →
CRA ülevaated
29 June 2026

With Reporting Due on 11 September 2026, ENISA's Single Reporting Platform Is Still Not Live

Mandatory vulnerability reporting starts on 11 September 2026, yet the one tool manufacturers must use to file those reports is not operational yet…

Loe →
CRA ülevaated
26 June 2026

On 11 June 2026, the CRA's Rules on Notified Bodies Started to Apply, but None Are Designated Yet

On 11 June 2026, Chapter IV of the CRA switched on the rules for notified bodies, the third-party assessors some products will need, yet none have been designated…

Loe →
CRA ülevaated
26 June 2026

A Newly Adopted Delegated Act Lets Authorities Hit Pause on Vulnerability Disclosure

On 11 December 2025 the Commission set out when an authority can delay sharing a reported vulnerability, even as the 24-hour reporting clock starts on 11 September 2026…

Loe →
CRA ülevaated
30 March 2026

One Product, Two Worlds: Will the EU’s Cyber Resilience Act Trigger a US Ban?

For global tech manufacturers, the "Holy Grail" is a single product design that can be sold everywhere. But a regulatory…

Loe →
CRA ülevaated
26 March 2026

The Router Revolution: Why the FCC Ban is a Global Game Changer

By Erel Rosenberg, Clea Rozenblum and SeongEun Kim i46 s.r.o. - For years, the conversation around router security was about…

Loe →
CRA ülevaated
7 January 2026

Why Risk Assessment Falls Short in Cybersecurity

While new regulations like the Cyber Resilience Act (CRA) and the AI Act make risk assessment a legal requirement, they often put manufacturers in a…

Loe →
CRA ülevaated
18 December 2025

Understanding the Notepad++ Updater Hijack

The Notepad++ Updater Hijack refers to a security vulnerability, specifically a DLL Hijacking attack, that was discovered and exploited in the update…

Loe →
CRA ülevaated
29 October 2025

DISK46: A Secure, LUKS-Preinstalled Linux Distribution for Raspberry Pi Risk Assessment

I. Product Identification DISK46 represents a specialized Linux distribution image, meticulously crafted with a…

Loe →
CRA ülevaated
23 October 2025

Securing the Edge: Disk Encryption Challenges Under the EU CRA

The European Union's Cyber Resilience Act (CRA) is redefining security mandates for all products with digital elements. For IoT device…

Loe →
Kiirkontroll
14 June 2024

IP-Time N608

is a router manufactured by IP-Time/EFM since 2010. The device does not comply with the CRA.

Loe →
Kiirkontroll
14 June 2024

Huawei B311 Home Router

IP-Time N608 is a router manufactured by IP-Time/EFM since 2010. The device does not comply with the CRA.

Loe →
Kiirkontroll
14 June 2024

SpeedPort LTE II

SpeedPort is a router manufactured by Huawei since at least 2013. The device does not comply with the CRA.

Loe →
Kiirkontroll
13 June 2024

IP-Time A3004NS-M

is a router manufactured by EFM in 2019. This is an old device, which does not need to conform with the CRA. However, if it had to, its current setup is found not compliant with the requirements of the CRA.

Loe →
Kiirkontroll
13 June 2024

TP-Link Archer AX73 V2

is a router manufactured by TP Link. While the device is reasonably secured, it does not comply with the CRA.

Loe →
Posts are imported from the cyberresilienceact.eu blog. 27 artiklit 2 categories.