European Cybersecurity Certification Conference 2026: 29 EUCC certs, enough CABs?
ENISA reported 29 EUCC certificates and 28 accredited CABs after EUCC's first year. What that capacity means for CRA conformity assessment.
What the CRA requires you to ship, and who has to do it. Scope decisions, manufacturer and importer duties, technical documentation, conformity assessment, and CE marking, explained article by article.
ENISA reported 29 EUCC certificates and 28 accredited CABs after EUCC's first year. What that capacity means for CRA conformity assessment.
ENISA's first EU cybersecurity certification scheme requires SBOMs, rejects ISO 27001 alone, and puts suppliers in the certification chain. CRA implications.
Archive of the March 2026 CRA consultation draft: 9 clarifications on SaaS, legacy products, open source, and reporting. The July draft now supersedes it.
CSA2 is still a proposal. COM(2026) 11 final would reshape cybersecurity certification, ICT supply chains and ENISA powers.
CRA playbook for companies that manufacture, import and distribute: role mapping, obligation stacking, vulnerability routing, penalties and conflict points.
An operational CRA distributor companion: receiving checklist, quick-reference card, real scenarios, and the acts that turn a distributor into a manufacturer.
Get notified when we publish new articles about CRA compliance and product security.