CRA-uutiset ja -näkemykset
Analyysi, sääntelypäivitykset ja CRA-pikatarkistusarvioinnit; valmistajille, ohjelmistokehittäjille, maahantuojille ja jakelijoille.
On 13 July 2026, ENISA Published a Free Maturity Model So SMEs Can Score Their CRA Readiness
On 13 July 2026, ENISA released a free self-assessment tool scoring SMEs across five CRA-relevant domains, from governance to vulnerability handling…
Tuoreet julkaisut
Fast Check: After CERT/CC's 6 July 2026 Tenda Backdoor Warning, Home Routers Fall Under the CRA's Class I Rules
CERT/CC's 6 July 2026 warning revealed a hidden admin backdoor in Tenda routers, and the vendor is not responding. Under the CRA, routers are Annex III Class I products…
Fast Check: After CISA's 3 July 2026 Fortinet Warning, FortiGate Firewalls Fall Under the CRA's Class II Rules
CISA flagged actively exploited Fortinet flaws on 3 July 2026. Under the CRA, a firewall like FortiGate is an Annex III Class II product, the tier that cannot self-assess…
On 24 June 2026, ENISA's First SME Survey Found High CRA Awareness but Low Readiness
ENISA's first SME survey, published on 24 June 2026, found high awareness of the CRA but thin practical readiness, with incident response and SBOM the weakest areas…
With Reporting Due on 11 September 2026, ENISA's Single Reporting Platform Is Still Not Live
Mandatory vulnerability reporting starts on 11 September 2026, yet the one tool manufacturers must use to file those reports is not operational yet…
On 11 June 2026, the CRA's Rules on Notified Bodies Started to Apply, but None Are Designated Yet
On 11 June 2026, Chapter IV of the CRA switched on the rules for notified bodies, the third-party assessors some products will need, yet none have been designated…
A Newly Adopted Delegated Act Lets Authorities Hit Pause on Vulnerability Disclosure
On 11 December 2025 the Commission set out when an authority can delay sharing a reported vulnerability, even as the 24-hour reporting clock starts on 11 September 2026…
One Product, Two Worlds: Will the EU’s Cyber Resilience Act Trigger a US Ban?
For global tech manufacturers, the "Holy Grail" is a single product design that can be sold everywhere. But a regulatory…
The Router Revolution: Why the FCC Ban is a Global Game Changer
By Erel Rosenberg, Clea Rozenblum and SeongEun Kim i46 s.r.o. - For years, the conversation around router security was about…
Why Risk Assessment Falls Short in Cybersecurity
While new regulations like the Cyber Resilience Act (CRA) and the AI Act make risk assessment a legal requirement, they often put manufacturers in a…
Understanding the Notepad++ Updater Hijack
The Notepad++ Updater Hijack refers to a security vulnerability, specifically a DLL Hijacking attack, that was discovered and exploited in the update…
DISK46: A Secure, LUKS-Preinstalled Linux Distribution for Raspberry Pi Risk Assessment
I. Product Identification DISK46 represents a specialized Linux distribution image, meticulously crafted with a…
Securing the Edge: Disk Encryption Challenges Under the EU CRA
The European Union's Cyber Resilience Act (CRA) is redefining security mandates for all products with digital elements. For IoT device…
IP-Time N608
is a router manufactured by IP-Time/EFM since 2010. The device does not comply with the CRA.
Huawei B311 Home Router
IP-Time N608 is a router manufactured by IP-Time/EFM since 2010. The device does not comply with the CRA.
SpeedPort LTE II
SpeedPort is a router manufactured by Huawei since at least 2013. The device does not comply with the CRA.
IP-Time A3004NS-M
is a router manufactured by EFM in 2019. This is an old device, which does not need to conform with the CRA. However, if it had to, its current setup is found not compliant with the requirements of the CRA.
TP-Link Archer AX73 V2
is a router manufactured by TP Link. While the device is reasonably secured, it does not comply with the CRA.
