Erp.Today Oracle Aligns Security Programs with EU Cyber Resilience Act Requirements
Article Content
- •The EU Cyber Resilience Act's reporting obligations began on September 11, 2026.
- •Oracle has established policies to comply with the CRA's incident reporting requirements.
- •Manufacturers must report actively exploited vulnerabilities within 24 hours.
The EU Cyber Resilience Act (CRA) mandates vulnerability and incident reporting for manufacturers of digital products, effective September 11, 2026. Oracle has prepared its Security Incident Management Policy and Integrated Cyber Center to meet these requirements. The CRA's initial reporting obligations focus on actively exploited vulnerabilities and severe incidents, with a 24-hour reporting deadline. Following this, broader cybersecurity obligations will take effect on December 11, 2027. Oracle's compliance efforts include documenting incidents, preserving evidence, and notifying relevant parties. However, customers with NIS2 or DORA obligations must still provide their own compliance evidence. The CRA applies to all connected products, including those already on the market, but manufacturers are not required to report incidents they were aware of before the September deadline. The reporting must be done through the EU's Single Reporting Platform, with notifications sent to the relevant Computer Security Incident Response Team (CSIRT).
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Oracle in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…