Cyber Resilience Act: New Guidelines Tighten Vendor Management Requirements30. July 2026Cybersecurity, RegulationThe CRA requires manufacturers from September 2026 onwards to report actively exploited vulnerabilities, demanding full transparency on machine identities and secrets in the supply chain earlier than the December 2027 deadline. Share on: