Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-18 ยท updated: 2026-08-18 ยท tags: [incident, regulation, cyber-resilience-act, standards, eu, supply-chain, sector-global] ยท confidence: high ยท affected_sectors: [global, technology] ยท au_impact: true

EU Publishes Draft Cyber Resilience Act Standards for Product Vendors

  • Source: Risky.Biz
  • Date: 2026-08-17
  • Reliability: Tier 2/4 โ€” Established cyber journalism
  • Entity: ETSI / EU Cyber Resilience Act (CRA)

Summary

The European Telecommunications Standards Institute (ETSI) released 17 draft cybersecurity standards that vendors must follow to sell products in the EU when the Cyber Resilience Act (CRA) enters effect next year. The standards cover 17 core technologies across major product categories and describe minimum security features required for CRA compliance.

Key Facts

  • 17 draft standards covering major product categories / core technologies
  • Minimum security features for CRA compliance: updatability after sale, SBOM, modern cryptography
  • Standards are interim drafts in a public-comments phase until November
  • Final versions expected by December, a year before CRA compliance
  • Marks the final regulatory step before the CRA enters effect

Sector

Global (Macro) โ€” EU product-security regulation with cross-border supply-chain impact.

Source

https://risky.biz/risky-bulletin-the-eu-publishes-its-upcoming-cybersecurity-standards/

Reliability

Tier 2 โ€” Established cyber journalism; official ETSI publication.

Date

2026-08-17

Related Pages

Sources: raw/digests/Cyber-Digest-2026-08-18