European Cybersecurity Certification Conference 2026: 29 EUCC certs, enough CABs?
ENISA reported 29 EUCC certificates and 28 accredited CABs after EUCC's first year. What that capacity means for CRA conformity assessment.
Analysis and practical guidance on the EU Cyber Resilience Act. Regulation explainers, SBOM tooling, vulnerability workflows, and ENISA reporting, written for manufacturers, importers, and distributors.
ENISA reported 29 EUCC certificates and 28 accredited CABs after EUCC's first year. What that capacity means for CRA conformity assessment.
ENISA's first EU cybersecurity certification scheme requires SBOMs, rejects ISO 27001 alone, and puts suppliers in the certification chain. CRA implications.
The Commission's draft CRA guidance (Ares(2026)2319816): 9 key rulings on SaaS scope, legacy products, open source, and reporting obligations, explained.
Generate a firmware SBOM using Yocto, Buildroot, EMBA, or Syft. ENISA vulnerability reporting starts September 11, 2026. Step-by-step workflows for CRA compliance.
CSA2 is still a proposal. COM(2026) 11 final would reshape cybersecurity certification, ICT supply chains and ENISA powers.
CRA playbook for companies that manufacture, import and distribute: role mapping, obligation stacking, vulnerability routing, penalties and conflict points.
Get notified when we publish new articles about CRA compliance and product security.