Ready for the Cyber Resilience Act
The EU Cyber Resilience Act is entering its next implementation phase. EnOcean is well prepared. Here’s what the upcoming milestone means, and how we got ready.
A new milestone is approaching
From 11 September 2026, manufacturers will be required to report actively exploited vulnerabilities. Severe security incidents affecting products with digital elements must also be reported. This is one of several phased milestones under the Cyber Resilience Act (CRA). The Act entered into force in December 2024 and applies in full of December 2027.
For EnOcean, this milestone is not a new undertaking. It builds directly on security practices we already have in place.
Built on an established foundation
Our approach to CRA readiness builds on our ISO/IEC 27001-certified information-security management system. Within this framework, we have established and continue to maintain processes for:
- Receiving and assessing reports of product-security vulnerabilities
- Communicating with reporters and, where relevant, affected users
- Fulfilling our regulatory reporting obligations under the CRA
- Maintaining the incident-management and compliance records needed to support all of the above
Together, these processes give us a structured, risk-based way to handle vulnerabilities. This runs from the moment a report comes in through to resolution and, where required, regulatory disclosure.
A clear path for reporting vulnerabilities
As part of our readiness for the September 2026 requirements, we have published our Coordinated Vulnerability Disclosure Policy. It explains how researchers, customers and partners can report a potential vulnerability to us. It also sets out what they can expect from EnOcean in return, including our assessment process and communication commitments.
Looking ahead to 2027
With our September 2026 readiness in place, we are now fully focusing our efforts on the broader CRA requirements applying from December 2027. These cover the wider set of obligations around product security, technical documentation and conformity assessment that manufacturers will need to meet. We are continuing to prepare our organization and portfolio accordingly.
Learn more
You can find more on our cybersecurity approach, reporting channels and response targets on our website: EnOcean Cybersecurity.