Honeywell EU Cyber Resilience Act Mandates New Cybersecurity Standards for Digital Products
Article Content
- •The Cyber Resilience Act mandates cybersecurity requirements for all digital products in the EU.
- •Manufacturers must conduct risk assessments and maintain SBOMs for compliance.
- •Full enforcement of the CRA begins on December 11, 2027, affecting global manufacturers.
The European Union has enacted the Cyber Resilience Act (CRA), which introduces mandatory cybersecurity requirements for all digital products sold in the EU market. The regulation, effective from December 11, 2027, requires manufacturers to ensure that products are designed, developed, and maintained with cybersecurity in mind. This includes conducting risk assessments, maintaining software bill of materials (SBOMs), and providing free patches for vulnerabilities during a defined support period. The CRA applies globally to any manufacturer wishing to sell products in the EU, regardless of their location. Compliance obligations will be phased in, with full requirements affecting products modified after the enforcement date. The European Commission is collaborating with industry stakeholders and ENISA to facilitate the CRA's implementation. Reporting obligations and conformity assessments are also part of the new regulatory framework.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…