The CRA requires manufacturers from September 2026 onwards to report actively exploited vulnerabilities, demanding full transparency on machine identities and secrets in the supply chain earlier than the December 2027 deadline.
The EU Council removed Article 88b (browser-based privacy settings instead of cookie banners) from the Digital Omnibus under pressure from Google and individual member states; data protection organisations are now mobilising the European Parliament.
The CRA guidance clarifies open questions on scope of application, material product changes, support periods, and reporting obligations ahead of the September 2026 deadline.
The EU is introducing mandatory indiscriminate monitoring of instant messengers from April 2028, requiring companies to conduct automated content screening.
Starting in September 2024, the Cyber Resilience Act mandates the reporting of security vulnerabilities within 24 hours to authorities, requiring fundamentally changed incident response processes.
The Cyber Resilience Act requires manufacturers to report security incidents within 24–72 hours starting September 2026, or face penalties up to 15 million euros.