CRA Update After the Summer Break

17 Sep, 2026
NEWS posts CRACoWi CRA Summer update

The Cyber Resilience Act landscape continues to move quickly and after the summer break, there is quite a lot to catch up on.

Our CRACoWi partner and CRA expert Michael Beine from Bureau Veritas has put together a practical overview of some of the latest developments, from the European Commission’s CRA Guidance and ENISA’s SME maturity assessment tool to the Single Reporting Platform, Notified Bodies and ongoing standardisation work.

If you lost track of some of the developments over the summer, this is a good place to catch up. Michael’s overview provides a quick read, together with links for those who want to explore individual topics in more detail.

CRA Guidance

The European Commission released the official CRA Guidance at the end of July.

This is a must-read for organisations preparing for CRA implementation. After the legal text itself, the Guidance provides an important source for interpreting the Regulation and brings additional clarity to many, although not all, questions surrounding CRA implementation.

Read more: European Commission – Commission publishes new guidance to support timely Cyber Resilience Act implementation

SME maturity model and tool

ENISA has published a guided self-assessment for CRA readiness, particularly intended to support small and medium-sized enterprises (SMEs).

The SME Cyber Resilience Maturity Assessment Model can help organisations assess their current level of preparedness and identify areas requiring further attention.

Read more:ENISA – SME Cyber Resilience Maturity Assessment Model

Single Reporting Platform (SRP)

ENISA continues to update its FAQs and guidance related to the Single Reporting Platform.

Among the relevant information currently available are the required datasets for the different types of reports.

To avoid unnecessary overload, the current recommendation is not to register in advance, but only when a report needs to be submitted.

Another small but practically relevant detail has recently been updated: up to 21 representatives can now be registered for one manufacturer, compared with two previously.

Read more:ENISA – Single Reporting Platform

CRA Notified Body

The nomination process for CRA Notified Bodies has started in several EU Member States through the relevant national authorities.

Bureau Veritas has submitted its application and is currently participating in the nomination process.

Relevant information on national processes is available from authorities including BSI, DAkkS and ANSSI, as well as through the available information on CRA notifying authorities.

Standardisation

Significant progress has also been made in the development of horizontal standards, including EN 40000-1-1, EN 40000-1-2 and EN 40000-1-3, with final versions becoming available.

Seventeen vertical standards developed by ETSI (i.e. EN 304 xxx) have reached the necessary maturity to enter Enquiry Phase.

Directory Listing /CYBER/EUSR/Open

Work is also continuing on the broad vertical standards (EN IEC 62443 prAA), with the relevant working group convening in Oslo.

Together, these developments show just how quickly the wider CRA implementation ecosystem is progressing and why keeping track of guidance, reporting mechanisms, conformity assessment and standardisation is becoming increasingly important for organisations preparing for compliance.

Meet the expert

Bureau Veritas offers a free 30-minutes “Talk to the expert”.  You are invited to book a suitable time-slot: https://www.bureauveritas.de/cyber-resilience-act-expert-talk

You may also like

Meet Us at the CRA Standards Unlocked Event in Lisbon

Meet Us at the CRA Standards Unlocked Event in Lisbon

📅17 September 2026 | 9:00 – 17:00 CEST | Venue Auditório da Sede Nacional da Ordem dos Engenheiros, Lisbon | Hybrid | English & Portuguese | FreeCRACoWi consortium partner SevenShift will be attending "CRA Standards Unlocked - EU Tour in Lisbon," a hybrid workshop...