The Cyber Resilience Act landscape continues to move quickly and after the summer break, there is quite a lot to catch up on.
Our CRACoWi partner and CRA expert Michael Beine from Bureau Veritas has put together a practical overview of some of the latest developments, from the European Commission’s CRA Guidance and ENISA’s SME maturity assessment tool to the Single Reporting Platform, Notified Bodies and ongoing standardisation work.
If you lost track of some of the developments over the summer, this is a good place to catch up. Michael’s overview provides a quick read, together with links for those who want to explore individual topics in more detail.
CRA Guidance
The European Commission released the official CRA Guidance at the end of July.
This is a must-read for organisations preparing for CRA implementation. After the legal text itself, the Guidance provides an important source for interpreting the Regulation and brings additional clarity to many, although not all, questions surrounding CRA implementation.
SME maturity model and tool
ENISA has published a guided self-assessment for CRA readiness, particularly intended to support small and medium-sized enterprises (SMEs).
The SME Cyber Resilience Maturity Assessment Model can help organisations assess their current level of preparedness and identify areas requiring further attention.
Read more:ENISA – SME Cyber Resilience Maturity Assessment Model
Single Reporting Platform (SRP)
ENISA continues to update its FAQs and guidance related to the Single Reporting Platform.
Among the relevant information currently available are the required datasets for the different types of reports.
To avoid unnecessary overload, the current recommendation is not to register in advance, but only when a report needs to be submitted.
Another small but practically relevant detail has recently been updated: up to 21 representatives can now be registered for one manufacturer, compared with two previously.
Read more:ENISA – Single Reporting Platform
CRA Notified Body
The nomination process for CRA Notified Bodies has started in several EU Member States through the relevant national authorities.
Bureau Veritas has submitted its application and is currently participating in the nomination process.
Relevant information on national processes is available from authorities including BSI, DAkkS and ANSSI, as well as through the available information on CRA notifying authorities.
- BSI – BSI – Notifizierung CRA
- DAkkS – DAkkS startet Akkreditierung für den Cyber Resilience Act – DAkkS – Deutsche Akkreditierungsstelle
- ANSSI – https://cyber.gouv.fr/reglementation/cybersecurite-des-produits/cyber-resilience-act/
- List of CRA notifying authorities
Standardisation
Significant progress has also been made in the development of horizontal standards, including EN 40000-1-1, EN 40000-1-2 and EN 40000-1-3, with final versions becoming available.
Seventeen vertical standards developed by ETSI (i.e. EN 304 xxx) have reached the necessary maturity to enter Enquiry Phase.
Directory Listing /CYBER/EUSR/Open
Work is also continuing on the broad vertical standards (EN IEC 62443 prAA), with the relevant working group convening in Oslo.
Together, these developments show just how quickly the wider CRA implementation ecosystem is progressing and why keeping track of guidance, reporting mechanisms, conformity assessment and standardisation is becoming increasingly important for organisations preparing for compliance.
Meet the expert
Bureau Veritas offers a free 30-minutes “Talk to the expert”. You are invited to book a suitable time-slot: https://www.bureauveritas.de/cyber-resilience-act-expert-talk




