{"id":73417,"date":"2026-08-05T22:34:35","date_gmt":"2026-08-05T20:34:35","guid":{"rendered":"http:\/\/adiumento.local\/?page_id=73417"},"modified":"2026-08-05T22:34:35","modified_gmt":"2026-08-05T20:34:35","slug":"cyber-resilience-act-umsetzung","status":"publish","type":"page","link":"https:\/\/adiumento.de\/en\/themen\/regulatorik-sicher-umsetzen\/cybersecurity-resilienz\/cyber-resilience-act-umsetzung\/","title":{"rendered":"Implement the Cyber Resilience Act in practice"},"content":{"rendered":"<div class=\"wp-block-cover alignfull is-position-center-left service-page-hero is-light alignfull\" style=\"min-height:420px;aspect-ratio:unset;\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" class=\"wp-block-cover__image-background wp-image-73452\" alt=\"Cybersecurity und Resilienz\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png\" data-object-fit=\"cover\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><span aria-hidden=\"true\" class=\"wp-block-cover__background has-dark-background-color has-background-dim-50 has-background-dim\"><\/span><div class=\"wp-block-cover__inner-container\"><p class=\"service-page-back is-layout-flow wp-block-cover-is-layout-flow\"><a href=\"https:\/\/adiumento.de\/en\/?page_id=73411\">\u2190 Cybersecurity &amp; Resilience<\/a><\/p><h1 class=\"wp-block-heading\">Implement the Cyber Resilience Act in practice<\/h1><p class=\"has-medium-font-size wp-block-paragraph\"><strong>Organize and document cybersecurity for products with digital elements throughout their entire life cycle.<\/strong><\/p><\/div><\/div>\n\n\n\n<div class=\"wp-block-group is-style-section-light service-page-orientation adiumento-passage is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-orientation__text wp-block-paragraph\">The Cyber Resilience Act (CRA) applies to products with digital elements made available on the EU market and to the relevant economic operators. Manufacturers must manage cybersecurity from planning and development through to maintenance and vulnerability handling. The Regulation has applied since 10 December 2024; notification provisions since 11 June 2026, Article 14 reporting obligations from 11 September 2026 and the remainder of the Regulation from 11 December 2027.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Background<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png\" alt=\"Cybersecurity und Resilienz\" class=\"wp-image-73452 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">Software and connected products often consist of proprietary components, open source libraries, third-party services and multiple release variants. Without a clear product inventory, responsibilities and a maintained vulnerability routine, it remains unclear what has been shipped, what support a product receives and how security vulnerabilities are responded to.<\/p>\n<\/div><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA is therefore shifting the focus from selective security checks to a verifiable product life cycle. He doesn't require every team to use the same tools. It is crucial that the appropriate cybersecurity requirements are implemented on a risk-based basis, documented and maintained during the support period.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Technical context<\/h2>\n\n<p class=\"wp-block-paragraph\">Regulation (EU) 2024\/2847 is a horizontal EU legal framework for hardware and software products with digital elements made available in the context of a commercial activity on the Union market. End products, separately provided components and certain associated remote data processing solutions may be covered. Exceptions and the exact role \u2013 such as manufacturer, importer or dealer \u2013 must be legally examined on a case-by-case basis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The main obligations apply to manufacturers who place a product on the market under their name or brand. They must, among other things, carry out a cybersecurity risk assessment, take into account essential requirements of Annex I, prepare technical documentation and carry out the appropriate pre-market conformity assessment procedure. After a successful assessment, the EU declaration of conformity and CE marking follow.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA entered into force on 10 December 2024. Provisions on the notification of conformity assessment bodies have applied since 11 June 2026; the Article 14 reporting obligations for actively exploited vulnerabilities and severe security incidents apply from 11 September 2026. The remaining principal obligations apply from 11 December 2027. The non-binding Commission guidelines of 27 July 2026 explain matters including scope, remote data processing, open source, support periods and interaction with other EU law.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The CRA complements NIS2 but does not replace any organisation-related NIS2 obligations. NIS2 is on the page <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/cybersecurity-resilienz\/nis2-umsetzung\/\">Implement NIS2 in practice<\/a> treated; the cluster classification provides <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/cybersecurity-resilienz\/\">Cybersecurity &amp; Resilience<\/a>.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">What companies need to clarify specifically<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1709\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg\" alt=\"IT-Security-Spezialistin \u00fcberwacht Systeme in einem Rechenzentrum.\" class=\"wp-image-73297 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg 2560w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-300x200.jpg 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1024x684.jpg 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-768x513.jpg 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1536x1025.jpg 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-2048x1367.jpg 2048w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-18x12.jpg 18w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li>Which products, components, versions and associated remote data processing solutions are within the scope of the review.<\/li>\n<li>What role the company plays for each product and who is responsible for the legal classification.<\/li>\n<li>How cybersecurity risks are assessed during planning, development, production, delivery and maintenance.<\/li>\n<li>How vulnerabilities are recorded, assessed, remedied, communicated and tracked over the support period.<\/li>\n<li>Which technical documentation, user information, conformity documents and proof of operation must be available.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">The responsible support period for each product should be determined early on and clearly communicated to users. According to Article 13, the treatment of vulnerabilities must generally be guaranteed for at least five years, unless the expected useful life is shorter. The specific duration, application and exceptions are part of the legal and product-related examination.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Lifecycle artifact set<\/h2>\n\n<ul class=\"wp-block-list\">\n<li>Product and version inventory and role decision;<\/li>\n<li>Cybersecurity risk assessment;<\/li>\n<li>SBOM or other component detection;<\/li>\n<li>Process for vulnerability handling and support period;<\/li>\n<li>technical documentation and compliance documents.<\/li>\n<\/ul>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">From requirements to implementation<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8.png\" alt=\"Abstrakte Illustration: Audit-Checkliste und Shield in Blau.\" class=\"wp-image-73237 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-security-audits-assessments-8-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Cybersecurity risk assessment<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Security requirements remain incomplete<br><strong>Organisational measure:<\/strong> Establish product, risk and release responsibility<br><strong>Technical implementation:<\/strong> Integrating threat modelling and risk-based security testing into the lifecycle<br><strong>Possible evidence:<\/strong> Risk assessment, architecture and release documents<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Safe development and delivery<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Vulnerabilities or manipulations find their way into releases<br><strong>Organisational measure:<\/strong> Define security gates, exceptions and release responsibility<br><strong>Technical implementation:<\/strong> Protected repositories and pipelines, code and dependency checks<br><strong>Possible evidence:<\/strong> Pipeline logs, review and release evidence<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Vulnerability treatment and updates<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Known gaps remain open<br><strong>Organisational measure:<\/strong> Operate triage, correction, communication and escalation processes<br><strong>Technical implementation:<\/strong> Vulnerability management, update distribution and version traceability<br><strong>Possible evidence:<\/strong> Tickets, advisories, update and patch reports<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Technical documentation and compliance<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Evaluation is not comprehensible<br><strong>Organisational measure:<\/strong> Determine documentation responsibility and nursing process<br><strong>Technical implementation:<\/strong> Manage product, component and configuration information in a versioned manner<br><strong>Possible evidence:<\/strong> Technical documentation, EU declaration of conformity, evidence for assessment<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Reports by Art. 14<\/summary><p class=\"wp-block-paragraph\"><strong>Risk:<\/strong> Actively exploited gaps or serious incidents are reported late<br><strong>Organisational measure:<\/strong> Determine reporting decisions, contacts and escalation path<br><strong>Technical implementation:<\/strong> Prepare detection, case creation and structured reporting data<br><strong>Possible evidence:<\/strong> Time stamps, messages, final reports<\/p><\/details>\n<\/div>\n\n\n\n\n<p class=\"wp-block-paragraph\">An SBOM can support transparency about components and dependencies, but is not an end in itself or an automatic statement of compliance. Offer in-depth knowledge <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/sbom-dependency-management\/\">SBOM &amp; Dependency Management<\/a> and <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/secure-software-lifecycle-devsecops\/\">Secure Software Lifecycle \/ DevSecOps<\/a>. Signatures can support the integrity and provenance of artifacts; However, the CRA does not require code signing as a stand-alone measure. For the strategy see <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/sichere-softwarebereitstellung\/code-signing-microsoft-artifact-signing\/\">Code Signing \/ Artifact Signing<\/a>.<\/p>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Working with ADIUMENTO<\/h2>\n\n<p class=\"wp-block-paragraph\">ADIUMENTO supports product, development and security teams in structuring existing delivery routes, dependencies, vulnerability processes and evidence. This can result in a risk-based lifecycle target picture, prioritised security measures and implementable work packages for development, operation and documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The work continues <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">IT Security &amp; Compliance<\/a> and <a href=\"https:\/\/adiumento.de\/en\/leistungen\/\">IT Security &amp; Compliance<\/a> to. ADIUMENTO does not provide legal advice, does not carry out binding product classification and does not issue any guarantee of conformity, CE performance or certification.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Typical Results<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1536\" height=\"1024\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png\" alt=\"Cybersecurity und Resilienz\" class=\"wp-image-73452 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz.png 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-300x200.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-1024x683.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-768x512.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/08\/adiumento-themen-cyber-resilienz-18x12.png 18w\" sizes=\"auto, (max-width: 1536px) 100vw, 1536px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li>delineated inventory of products, versions, components and responsibilities;<\/li>\n<li>Lifecycle target image for security gates, vulnerability management and updates;<\/li>\n<li>prioritised roadmap for toolchain, documentation and operations;<\/li>\n<li>Evidence structure for risk assessments, approvals, updates and reports;<\/li>\n<li>Working basis for coordination with legal advice, conformity assessment and market surveillance.<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Limitations and dependencies<\/h2>\n\n<p class=\"wp-block-paragraph\">Whether a specific product is within the scope of application, what role a company plays, what support period applies and what conformity assessment procedure is required must be assessed legally and product-related. Technical measures alone do not replace this assessment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The quality of the evidence depends on complete product information, maintained component and version data, reliable supplier information and an actual operational process. ADIUMENTO does not replace legal advice, a notified body, market surveillance authority or conformity assessment.<\/p>\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-neutral adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Further official sources<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-right service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1709\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg\" alt=\"IT-Security-Spezialistin \u00fcberwacht Systeme in einem Rechenzentrum.\" class=\"wp-image-73297 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-scaled.jpg 2560w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-300x200.jpg 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1024x684.jpg 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-768x513.jpg 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-1536x1025.jpg 1536w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-2048x1367.jpg 2048w, https:\/\/adiumento.de\/wp-content\/uploads\/2026\/07\/adiumento-it-security-monitoring-rechenzentrum-cybersecurity-18x12.jpg 18w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/eur-lex.europa.eu\/legal-content\/DE\/TXT\/? Uri=CELEX%3A32024R2847\">Regulation (EU) 2024\/2847 \u2013 Cyber Resilience Act<\/a> \u2013 EUR-Lex<\/li>\n<li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/de\/policies\/cyber-resilience-act\">European Commission: Cyber Resilience Act<\/a> \u2013 European Commission<\/li>\n<li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/de\/policies\/cra-summary\">European Commission: CRA \u2013 summary<\/a> \u2013 European Commission<\/li>\n<li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation\">EU Commission: Guidelines on CRA implementation from July 27, 2026<\/a> \u2013 European Commission<\/li>\n<li><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/cra-reporting\">EU Commission: CRA Reporting and Single Reporting Platform<\/a> \u2013 European Commission<\/li>\n<\/ul>\n<\/div><\/div>\n\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light service-page-topics adiumento-passage adiumento-themen-faq is-layout-flow wp-block-group-is-layout-flow\"><p class=\"has-text-align-center service-section-kicker wp-block-paragraph\">Orientation<\/p>\n<h2 class=\"wp-block-heading has-text-align-center\">Frequently asked questions<\/h2>\n\n<div class=\"wp-block-group wp-block-coblocks-accordion adiumento-accordion is-layout-flow wp-block-group-is-layout-flow\">\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">When do manufacturers have to report under Article 14 CRA?<\/summary><p class=\"wp-block-paragraph\">The reporting requirements for actively exploited vulnerabilities and serious security incidents apply from September 11, 2026. The Commission summarizes deadlines of 24 hours for an early warning and 72 hours for a report; The applicable requirements and content should be checked on a case-by-case basis.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Does the CRA already apply in full?<\/summary><p class=\"wp-block-paragraph\">No. The regulation came into force on December 10, 2024. Notification requirements apply from June 11, 2026, Article 14 reporting requirements from September 11, 2026; the remaining main obligations apply from December 11, 2027.<\/p><\/details>\n\n<details class=\"wp-block-details wp-block-coblocks-accordion-item\"><summary class=\"wp-block-coblocks-accordion-item__title is-layout-flow wp-block-details-is-layout-flow\">Is code signing mandatory after the CRA?<\/summary><p class=\"wp-block-paragraph\">The CRA does not mention code signing as an express individual obligation. A signature can support the integrity and provenance of artifacts in an appropriate security architecture. Which controls are suitable depends on the risk assessment, the basic requirements and the respective product.<\/p><\/details>\n<\/div>\n\n<\/div>\n\n\n<div class=\"wp-block-group is-style-section-light adiumento-passage adiumento-themen-section is-layout-flow wp-block-group-is-layout-flow\"><h2 class=\"wp-block-heading has-text-align-center\">Next sensible step<\/h2>\n\n<div class=\"wp-block-media-text is-stacked-on-mobile has-media-on-the-left service-media-text adiumento-themen-media\"><figure class=\"wp-block-media-text__media\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"768\" src=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7.png\" alt=\"Abstrakte Illustration: Threat Detection und Schutzschild in Blau.\" class=\"wp-image-73233 size-full\" srcset=\"https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7.png 1024w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-300x225.png 300w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-768x576.png 768w, https:\/\/adiumento.de\/wp-content\/uploads\/2025\/08\/adiumento-cloud-defender-security-7-16x12.png 16w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure><div class=\"wp-block-media-text__content\">\n<p class=\"wp-block-paragraph\">First, be transparent about product scope, responsibilities, components, support periods, and current vulnerability processes. <a href=\"https:\/\/adiumento.de\/en\/loesungen\/\">IT Security &amp; Compliance<\/a> can technically structure lifecycle and supply chain readiness; it does not replace legal assessment or conformity assessment. The <a href=\"\/en\/themen\/regulatorik-sicher-umsetzen\/\">Regulatory hub<\/a> shows the other topics.<\/p>\n<\/div><\/div>\n\n\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Implement the Cyber Resilience Act in practice: structure the product lifecycle, vulnerability management, updates, technical documentation and evidence.<\/p>","protected":false},"author":3,"featured_media":0,"parent":73411,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-73417","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73417","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/comments?post=73417"}],"version-history":[{"count":4,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73417\/revisions"}],"predecessor-version":[{"id":73503,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73417\/revisions\/73503"}],"up":[{"embeddable":true,"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/pages\/73411"}],"wp:attachment":[{"href":"https:\/\/adiumento.de\/en\/wp-json\/wp\/v2\/media?parent=73417"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}