Skip to content
Oracle Aligns Security Programs with EU Cyber Resilience Act Requirements

Oracle Aligns Security Programs with EU Cyber Resilience Act Requirements

First seen 22 Sep 2026, 21:25 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 22, 2026 at 22:55 UTC
  • The EU Cyber Resilience Act's reporting obligations began on September 11, 2026.
  • Oracle has established policies to comply with the CRA's incident reporting requirements.
  • Manufacturers must report actively exploited vulnerabilities within 24 hours.

The EU Cyber Resilience Act (CRA) mandates vulnerability and incident reporting for manufacturers of digital products, effective September 11, 2026. Oracle has prepared its Security Incident Management Policy and Integrated Cyber Center to meet these requirements. The CRA's initial reporting obligations focus on actively exploited vulnerabilities and severe incidents, with a 24-hour reporting deadline. Following this, broader cybersecurity obligations will take effect on December 11, 2027. Oracle's compliance efforts include documenting incidents, preserving evidence, and notifying relevant parties. However, customers with NIS2 or DORA obligations must still provide their own compliance evidence. The CRA applies to all connected products, including those already on the market, but manufacturers are not required to report incidents they were aware of before the September deadline. The reporting must be done through the EU's Single Reporting Platform, with notifications sent to the relevant Computer Security Incident Response Team (CSIRT).

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-11
EU Cyber Resilience Act reporting obligations effective
Manufacturers must report actively exploited vulnerabilities and severe incidents under the CRA.
Erp.Today
2026-09-22
Oracle announces compliance readiness
Oracle highlights its Security Incident Management Policy and Integrated Cyber Center for CRA compliance.
Erp.Today
2026-09-22
Debate on CRA's impact on manufacturers
The CRA applies to all connected products, requiring manufacturers to adapt their incident response processes.
Debevoisedatablog

More articles in this cluster (2)

Following this threat?

Track Oracle in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed