LIVE · cybersecurity feed
Live wire
security

17 draft Cyber Resilience Act standards are open for comment

A company selling a connected toy in Europe must show by the end of 2027 that the product meets the Cyber Resilience Act. The law states what manufacturers have to achieve and stops there, which leaves the toymaker to work out the technical detail alone. Seventeen draft standards, now open for comment, supply that detail. What following a standard buys you Manufacturers who follow a Harmonised Sta

zeroday.news ·

Seventeen draft standards intended to support the European Union's Cyber Resilience Act (CRA) are currently open for public comment. These drafts aim to provide the technical specifics necessary for manufacturers to demonstrate compliance with the CRA, which mandates cybersecurity requirements for products with digital elements sold within the European Economic Area.

The CRA, which becomes fully effective by the end of 2027, outlines the cybersecurity outcomes manufacturers must achieve but does not detail the technical methods. The draft standards are designed to fill this gap, offering a clear path for compliance. Manufacturers who adhere to these Harmonised Standards, once finalized, will benefit from a "presumption of conformity," meaning their products will be considered compliant with the law unless proven otherwise.

The current drafts are candidates for this harmonized status and cover products categorized as higher-risk, including password managers, antivirus software, smart home assistants, connected toys, and wearables. The process of developing these standards is led by groups such as TC CYBER-EUSR, which focuses on translating the CRA's legislative requirements into actionable technical specifications.

The drafts were distributed to 41 member organizations, including national standardization bodies across the European Economic Area, for an initial phase of feedback. Additionally, four societal partner organizations—ANEC (consumer interests), ECOS (environmental), ETUC (labor), and SBS (small businesses)—are invited to provide input, ensuring a broad range of perspectives are considered before the standards are finalized.

The comment period for these drafts is staggered, with closing dates varying by product vertical, generally falling between mid-September and mid-November 2026. This timeline emphasizes the importance for affected parties to engage now, as the final text will reflect the input received during this phase.

The CRA's scope extends beyond firmware developers to include importers, distributors, service providers, and developers of commercially available hardware and software, all of whom face the same compliance deadline of late 2027. For many small and medium-sized enterprises, navigating the compliance route, including identifying relevant standards, testing tools, and potential funding, remains an ongoing challenge.

ShareXLinkedInWhatsAppFacebook

More News

view all →
nation-state

Product showcase: ScamNet looks for warning signs in suspicious calls and shady links

ScamNet: Anti-Scam Suite is a consumer security app from Synaptrex Technologies that helps users detect and block scams involving phone calls, text messages, websites, and other suspicious content. The app is available for iPhone, iPad, and Mac, with features varying by platform. Call protection is available on iPhone, while tools such as Visual Intelligence are supported on iPhone and iPad. The a

vulnerability

Microsoft blames AI for delayed Exchange update, can’t say when it will arrive

Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service

breach

Chinese AI company Zhipu claims its new is a better bug-finder than Anthropic, OpenAI

PLUS: HCL, TCS, admit data breaches; Google, Apple, India bans some rideshare tips; and more!

breach

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data. [...]

ddos

DDoS Attacks Cause Major Threema Outages

Large DDoS attacks disrupted Threema, causing severe communication outages. Threema On-Prem users were unaffected by the attacks. Threema suffered multiple large-scale DDoS attacks that disrupted its secure messaging service and caused severe communication issues. Organizations using Threema On-Prem were not affected, as their deployments run on their own infrastructure. Threema is a Swiss paid se

security

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]