The first major EU Cyber Resilience Act (the “CRA“) compliance deadline is fast approaching. From 11 September 2026, manufacturers within scope of the CRA must comply with new reporting obligations for actively exploited vulnerabilities and severe incidents. These requirements take effect more than a year before the CRA’s substantive provisions, making them an

Continue Reading EU: Preparing for the Cyber Resilience Act’s September 2026 Reporting Obligations

The UK Government’s legislative agenda, set out in the King’s Speech on 13 May 2026, places cybersecurity and digital resilience firmly at the centre of national policy. Against a backdrop of increasing geopolitical instability and rapidly evolving technological risks, the proposed measures continue the shift towards a more interventionist and systemic approach to safeguarding the

Continue Reading UK: The King’s Speech 2026 – Cybersecurity at the Forefront

On 20 November 2024, the EU Cyber Resilience Act (CRA) was published in the Official Journal of the EU, kicking off the phased implementation of the CRA obligations.

What is the CRA?

The CRA is a harmonising EU regulation, the first of its kind focusing on safeguarding consumers and businesses from cybersecurity threats. 

Continue Reading EU: Cyber Resilience Act published in EU Official Journal