ctipilot.ch

EU Cyber Resilience Act

policy · policy:eu-cyber-resilience-act single-sourcesingle-source-national-cert

EU product-security regulation; first hard deadline (designation of notifying authorities) fell on 11 June 2026, with the CRA Single Reporting Platform following on 11 September 2026. Tracked for its direct compliance impact on European software and hardware vendors.

Aliases: CRA

Coverage timeline
26
first 2026-05-04 → last 2026-08-09
Peak priority
high
1 high · 25 notable
Sources cited
86
64 hosts
Sections touched
5
active-threats, research, weekly-annual-reports
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
2
pinned v19.2 · see below

Hunting pivots

Affected products
Alibaba fastjsonIBM WebSphere Application ServerLangflowPTC WindchillPhoenix Contact CHARX SEC-3000Ruby on Rails Active StorageSiemens Desigo CC

ATT&CK techniques

2 techniques observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Impact TA0040

T1498Network Denial of Service×1

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users. Network DoS can be performed by exhausting the network bandwidth services rely on. Example resources include specific websites, email services, DNS, and web-based applications. Adversaries have been observed conducting network DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-06-14/looking-ahead-2026-w24 · ATT&CK page ↗

T1499Endpoint Denial of Service×1

Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users. Endpoint DoS can be performed by exhausting the system resources those services are hosted on or exploiting the system to cause a persistent crash condition. Example services include websites, email services, DNS, and web-based applications. Adversaries have been observed conducting DoS attacks for political purposes and to support other malicious activities, including distraction, hacktivism, and extortion.

Evidence: 2026-06-14/looking-ahead-2026-w24 · ATT&CK page ↗

Story timeline

  1. 2026-08-092026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out
    weekly-looking-aheadW32 outlook — the 15 August Dutch NIS2 clock, WALLIX details due in September, and five products with no fix coming
  2. 2026-08-022026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks
    weekly-looking-aheadW31 outlook — the 12 August CHARX firmware deadline, WebSphere on interim fixes, and Cl0p's pending listings
  3. 2026-08-02The European Commission published its first official Cyber Resilience Act application guidance six weeks before the regulation's reporting obligations begin — clarifying which products are in scope, including remote data processing and free and open-source software
    weekly-policyCommission issues first CRA application guidance, six weeks before the CRA reporting obligations start
  4. 2026-07-262026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tightening
    weekly-looking-aheadW30 outlook — the nginx RCE PoC clock, Oracle Fusion Middleware abuse 'very likely', a public Certighost AD CS PoC, a pending Mitel CVE, and the CRA/NIS2 clocks
  5. 2026-07-26ENISA moved cyber-assurance into procurement leverage this week — a public consultation on a mandatory EU Managed Security Services certification, and concrete hospital-procurement security guidance under a new Health Action Plan
    weekly-policyTwo ENISA moves turn guidance into procurement gates — a mandatory EUMSS certification for Reserve providers, and EU hospital-procurement security rules
  6. 2026-07-192026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks running
    weekly-looking-aheadW29 outlook — public PoCs (WP2Shell, Firefox), a SharePoint chain half-patched until August, a withheld ShareFile CVE, and the CRA/CER clocks already ticking
  7. 2026-07-19EU critical-entity and product-resilience regulation reached concrete operator-facing milestones this week — ENISA shipped a CRA readiness self-assessment ahead of the 11 September reporting clock, and Germany's KRITIS-Dachgesetz opened its first CER-Directive registration window
    weekly-policyTwo EU CI-resilience clocks advanced — ENISA's SME CRA maturity model ahead of the 11 Sept Article 14 duty, and Germany's KRITIS-Dachgesetz registration window
  8. 2026-07-12Looking ahead — 2026-W28
    weekly-looking-aheadLooking ahead — 2026-W28: items already in motion for the coming weeks
  9. 2026-06-29Looking ahead — 2026-W26
    weekly-looking-ahead
  10. 2026-06-29EU Cyber Resilience Act — 75 days to the 11 September vulnerability/incident-reporting obligation
    weekly-policy
  11. 2026-06-22Looking ahead — 2026-W25
    weekly-looking-ahead
  12. 2026-06-22G7 Évian cybersecurity declaration calls PQC an "urgent priority" — and the expected hacktivist DDoS materialised on day one
    weekly-policy
  13. 2026-06-22CRA reporting obligation lands 11 September — ENISA Single Reporting Platform access manual due, dry-runs before go-live
    weekly-policy
  14. 2026-06-14Looking ahead — 2026-W24
    weekly-looking-ahead
  15. 2026-06-14Germany's Bundestag opens first reading of the CRA domestic-implementation bill
    weekly-policy
  16. 2026-06-14ENISA publishes the first EU-wide SBOM Adoption State of Play — consumption lags generation
    weekly-policy
  17. 2026-06-10EU Cyber Resilience Act reaches its first hard deadline — notifying-authority designation due 11 June
    active-threats
  18. 2026-06-01Looking ahead — 2026-W23
    weekly-looking-ahead
  19. 2026-06-01CRA June 11 notifying-authority deadline — first hard CRA milestone with ENISA SRP manual and Secure Update Mechanisms advisory published
    weekly-policy
  20. 2026-05-25EU Cyber Resilience Act — 11 June notifying-authority deadline, then September reporting obligations
    weekly-policy
  21. 2026-05-11Verizon DBIR 2026 (19th annual edition)
    weekly-annual-reports
  22. 2026-05-11Looking ahead — 2026-W20
    weekly-looking-ahead
  23. 2026-05-11EU CRA milestones — 11 June 2026 CAB notification, 11 September 2026 Article 14 reporting obligations
    weekly-policy
  24. 2026-05-09ENISA expands CVE Root: four new European organisations onboarded as CVE Numbering Authorities
    research
  25. 2026-05-04EU Cybersecurity Package 2026 — NIS2 amendment (COM(2026) 13) + Cybersecurity Act 2 enter EP preparatory phase; PQC obligation embedded
    weekly-policy
  26. 2026-05-04ENISA expands CVE Numbering Authority root — 4 new CNAs, 7 migrated from MITRE; ~90 European CNAs eligible for transfer
    weekly-policy

Relationships explore in graph

Typed, source-stated connections from the entity registry — each edge cites the entry whose reporting establishes it.

related to

Where this entity is cited

  • weekly-policy13
  • weekly-looking-ahead10
  • research1
  • weekly-annual-reports1
  • active-threats1

Source distribution

  • enisa.europa.eu7 (8%)
  • digital-strategy.ec.europa.eu4 (5%)
  • advisories.ncsc.nl3 (3%)
  • bleepingcomputer.com3 (3%)
  • helpnetsecurity.com3 (3%)
  • msrc.microsoft.com3 (3%)
  • securityweek.com3 (3%)
  • edpb.europa.eu2 (2%)
  • other58 (67%)
All cited sources (86)

Entries about EU Cyber Resilience Act (26)

2026-08-09 · view entry permalink →

NOTABLENATOA1

2026-W32 looking ahead — items already in motion: a NIS2 law in force in six days, a PAM appliance whose full exploitation detail is due in September, five products that will never be patched, and a federal ISMS deadline five months out

Items already in motion at the close of ISO week 2026-W32, each with a source and a date. None of these is a prediction.

Dated obligations.

  • 15 August 2026 — the Netherlands' Cyberbeveiligingswet enters into force, together with the companion critical-entities resilience law, imposing registration, duty-of-care, incident-notification and board-accountability duties on more than 8,000 organisations across 18 sectors, with registration in NCSC-NL's national entity register mandatory from that date (Rijksoverheid, 2026-07-07). Relevant to anyone with Dutch entities, suppliers or public-sector counterparts, whose notification behaviour changes on that date.
  • 11 September 2026 — the Cyber Resilience Act's reporting obligations begin, ahead of the regulation's principal obligations in December 2027. 13 September 2026 — ENISA's consultation on the draft EU Managed Security Services certification scheme closes, two days later; providers delivering services under the EU Cybersecurity Reserve would need that certification within two years of the scheme's entry into force, which makes it a procurement gate rather than a voluntary mark. Both were established in prior weekly coverage and neither date has moved.
  • 2 December 2026 — two new prohibited AI practices apply under the AI Act as amended, and 2 December 2027 / 2 August 2028 are the new application dates for high-risk obligations under Annex III and Annex I respectively, following Regulation (EU) 2026/1744 (EUR-Lex, 2026-07-24). Any readiness plan written against 2 August 2026 for Annex III systems is now diarised to the wrong date.
  • 1 January 2027 — Swiss federal administrative units must have built their ISMS. The Informationssicherheitsverordnung requires the administrative units under its Article 2(1)(c) to build their information-security management system within three years of the ordinance's entry into force, and the ordinance entered into force on 1 January 2024 (Fedlex, ISV SR 128.1). Roughly five months remain. The addressee is the federal administration itself; commentary that presents this as a general critical-infrastructure obligation is reading it more broadly than the text supports.

Disclosure and exploitation clocks.

  • September 2026 — full technical details of the WALLIX Bastion authentication bypass are due. WALLIX states that the reporting researchers intend to publish the complete write-up of the CVSS 4.0 base 10.0 flaw that gives an unauthenticated caller full product-administrator control of the appliance — its credential vault and session recordings included — in September (WALLIX, 2026-07-20). Bastion 12.3.7 and 12.4.1 and later are patched, per the CERT-FR advisory that relayed the bulletin (CERT-FR, 2026-08-06). This is a dated window for remediating quietly, not a current threat.
  • Cl0p's Windchill and FlexPLM listings have still not begun. Research re-checked this week found no leak-site listing for that campaign, leaving affected organisations in the interval between exfiltration and publication — the status a prior weekly recorded, unchanged.

Flaws with no fix coming. Five items from this week's coverage will not be resolved by waiting for a vendor, and each therefore converts into an architecture or lifecycle decision:

  • Tobit TeamDavid — 22 CVEs bounded at "Rollout 524" with no fixed release named, against roughly 12,000 internet-facing instances, and researchers reporting that both they and the coordinating national cyber security centre were left without a vendor response (InfoGuard Labs, 2026-08-07).
  • Flowise — three CVEs assigned days after the vendor announced it is winding down; self-hosted operators own the compensating controls.
  • Zbtlink routers (ENDLESSDOORS) — a factory-shipped root backdoor on twenty models, where the discloser's remediation is device replacement.
  • CPDLC over ATN-B1 — five flaws that are properties of the standard, with CISA recording the remediation category as none-available.
  • Check Point's end-of-support management trains — R80 through R81.10 are listed as affected by this week's unauthenticated management-authentication bypass with no fix on offer.

In development, no date. NCSC UK confirms it is working with international partners on a reference architecture for forensic observability in network appliances, intended to give vendors something concrete to build to (NCSC UK, 2026-07-29). It is not published, and no publication date is stated. Separately, the Metabase SQL-injection zero-day exploited this week still has no CVE identifier assigned, so it will not reach any process that waits for one.

Builds on: 2026-08-09/wallix-bastion-rest-api-unauth-admin-cvss10 · 2026-08-09/teamdavid-tobit-22-cves-unauth-mailbox-takeover-dach · 2026-08-08/flowise-three-cves-vendor-sunset-no-fix-coming · 2026-08-06/endlessdoors-zbtlink-router-factory-shipped-root-backdoor · 2026-08-08/cpdlc-atn-b1-five-protocol-flaws-no-mitigation-available · 2026-08-05/check-point-cve-2026-18574-management-auth-bypass · 2026-08-09/metabase-unauth-sqli-zeroday-exploited-framework-tally

outlook09 Aug 23:45Zmulti-sourceOpen finding ↗

2026-08-02 · view entry permalink →

NOTABLEexploitedNATOB2

2026-W31 looking ahead — items already in motion: a committed firmware date of 12 August, WebSphere fix packs not due before 3Q2026, an extortion campaign between exfiltration and publication, three flaws with no fix at all, and the CRA reporting clock at six weeks

Items already in motion at the close of 2026-W31, each with a source and a date. None of these is a prediction.

A firmware release with a committed deadline — 12 August. CERT@VDE's advisory covering 20 vulnerabilities in Phoenix Contact CHARX SEC-3xxx EV charging controllers, five of them CVSS 9.8 with an unauthenticated network vector, published without the fix: "the updated firmware will be made available as soon as possible, but no later than August 12, 2026." (CERT@VDE, 2026-07-30). Until then the vendor's only offered control is closed-network operation behind a firewall — and one of the flaws makes the on-device firewall unavailable for a window during every shutdown. The date is checkable and worth checking.

Permanent WebSphere fix packs not expected before 3Q2026. IBM has no workaround for the CVSS 9.8 missing-authentication flaw in the WebSphere Application Server traditional administrative console, and targets the permanent Fix Packs 9.0.5.29 and 8.5.5.31 for 3Q2026, leaving the interim fix under APAR DT496500 as the only remediation now (IBM PSIRT, 2026-07-28); a companion bulletin the same day carries the deserialization flaw and APAR PH72166 (IBM PSIRT, 2026-07-28). Estates that defer interim fixes on principle are deferring past a quarter boundary.

An extortion campaign between exfiltration and publication. Cl0p-affiliated actors have been sending staff-wide emails naming PTC Windchill as the breach vector, but as of the last reported observation the second shoe had not dropped: "as of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign." (Ransom-ISAC, 2026-07-22). Any organisation that ran an internet-exposed, unpatched Windchill or FlexPLM instance in June sits inside that gap, and the campaign's own precedent is that listings follow.

Three flaws with no fix, and one of them exploited. Langflow's pre-authentication eval injection is being exploited with no documented fixed version, and ZDI's only stated mitigation is to restrict interaction with the product (Zero Day Initiative, 2026-01-09). fastjson 1.x will not receive one: "FastJson 1.x is no longer actively maintained, and no patched 1.x version has been released for this vulnerability." (Imperva, 2026-07-24). And Siemens records the entire Desigo CC V7 family under remediation category none_available, with network segmentation as the only offered control (Siemens ProductCERT, 2026-07-14). These three leave the vulnerability queue by being made unreachable or not at all.

An embargo that has already broken. The Rails security team abandoned its plan to withhold the CVE-2026-66066 Active Storage exploitation details until 2026-08-28, publishing the attack write-up four weeks early along with a forensic-evidence guide and tooling to determine whether an application was vulnerable and whether it was exploited (Ruby on Rails security team, 2026-07-31). The window in which the chain was private is closed; what remains in motion is the population of unpatched applications, and the published forensic check is how an operator establishes which side of it they are on.

The CRA reporting clock, at six weeks. "Although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026." (Hunton Andrews Kurth, 2026-07-29). From that date the regulation's reporting obligations bind manufacturers of products with digital elements — which for this constituency is a change in what EU-market suppliers owe their customers, arriving more than a year before the rest of the regulation applies. The notification window and article number are deliberately not stated here: no source fetched this run carries them.

The updated firmware will be made available as soon as possible, but no later than August 12, 2026.

CERT@VDE 2026-07-30

As of 22 July, Cl0p ransomware has not begun listing victims of this latest campaign on their dark web data leak site or has publicly claimed credit for this latest campaign.

Ransom-ISAC / eCrime.ch / DEFUSED 2026-07-22

Although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026.

Hunton Andrews Kurth 2026-07-29

Builds on: 2026-08-02/phoenix-contact-charx-sec-3xxx-unauth-root-no-firmware-yet · 2026-08-01/ibm-websphere-cve-2026-14512-14446-preauth-no-fix-pack · 2026-07-27/clop-windchill-flexplm-mass-extortion-wave-cve-2026-12569 · 2026-07-29/cve-2026-0769-langflow-preauth-eval-rce-exploited-not-in-kev · 2026-07-27/cve-2026-16723-fastjson-1x-spring-boot-fat-jar-rce-no-patch · 2026-07-29/cve-2025-15467-siemens-desigo-cc-cms-overflow-v7-unfixed · 2026-08-02/cve-2026-66066-rails-attack-chain-public-forensic-tooling

outlook02 Aug 23:59Zmulti-sourceOpen finding ↗

2026-08-02 · view entry permalink →

NOTABLENATOA2

The European Commission published its first official Cyber Resilience Act application guidance six weeks before the regulation's reporting obligations begin — clarifying which products are in scope, including remote data processing and free and open-source software

The Cyber Resilience Act's first operational deadline has been on defenders' calendars for months without an authoritative account of who it applies to. The Commission published one on 2026-07-27, as Communication C(2026) 5252 with an annex, and the parts that resolve real ambiguity are the scope boundaries: the guidance covers "clarifying when certain products fall within the scope of the Cyber Resilience Act, including remote data processing solutions and free and open source software" (European Commission, 2026-07-27). Those two categories are exactly where suppliers have been arguing they fall outside the regulation — a hosted component with a device-side client, and an open-source dependency with no commercial vendor behind it. The document is built for practical application rather than legal argument, with "particular attention has been paid to microenterprises and SMEs, with 67 practical examples, a range of use cases, flowcharts and graphs" (European Commission, 2026-07-27). It also addresses what counts as a substantial modification — the change that restarts conformity obligations — and how support-period duration should be determined.

The timing is the point. Legal analysis of the guidance sets out the sequence plainly: "although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026." (Hunton Andrews Kurth, 2026-07-29). So the first thing the CRA actually requires of manufacturers is incident and vulnerability reporting, and it starts in roughly six weeks, more than a year before the bulk of the regulation binds. Guidance clarifying scope arriving now is guidance about who has to stand up a reporting capability before mid-September.

For a Swiss federal SOC the CRA creates no direct obligation, and the honest framing of its relevance is indirect but real. It runs through the supplier tail: EU-market suppliers of connected products to Swiss and European public-sector and critical-infrastructure customers are the regulated parties, and the scope clarifications determine which of them are inside the reporting regime. Two consequences are worth tracking rather than acting on. First, a supplier newly understanding itself to be in scope — particularly one shipping a remote data processing solution it had assumed was a service rather than a product — will be standing up an incident-reporting process on a six-week timeline, which is a period in which disclosure behaviour tends to be inconsistent. Second, the substantial-modification clarification bears on when a supplier's own update and patch practice re-triggers conformity assessment, which is a plausible source of future friction between a customer wanting a fix quickly and a vendor facing a re-assessment to ship it.

Clarifying when certain products fall within the scope of the Cyber Resilience Act, including remote data processing solutions and free and open source software

Particular attention has been paid to microenterprises and SMEs, with 67 practical examples, a range of use cases, flowcharts and graphs

European Commission

Although the principal obligations will apply from December 11, 2027, reporting obligations take effect on September 11, 2026.

Hunton Andrews Kurth 2026-07-29
policy02 Aug 23:59Zmulti-sourceOpen finding ↗

Earlier coverage (23)

2026-07-26NOTABLEexploitedNATOA22026-W30 looking ahead — items already in motion: a nginx pre-auth RCE PoC on a ~21-day release clock, Oracle Fusion Middleware abuse assessed 'very likely', a public AD CS DCSync PoC, a Mitel CVE pending, and two EU compliance clocks tighteningA justified watch list of items already in motion at the close of 2026-W30 — not predictions. The nginx / NGINX Plus pre-auth heap-overflow CVE-2026-42533 has a working pre-auth RCE demonstrated by its discoverer, with the exploit PoC withheld for roughly 21 days from mid-July disclosure — a public-exploit clock, not a current threat. Oracle's July CPU carries nine unauthenticated CVSS-10.0 Fusion Middleware flaws that NCSC-NL assesses as very likely to see large-scale abuse in the short term. The Windows AD CS "Certighost" flaw CVE-2026-54121 now has a full public PoC that forges a Domain Controller certificate to DCSync, weaponizable against any un-patched AD CS estate. Mitel's unauthenticated MiCollab AWV command-injection flaw (CVSS 9.8) still has no assigned CVE. And two EU compliance clocks tighten: the Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026, and the CRA Article 14 24-hour exploited-vulnerability reporting obligation begins 11 September 2026, two days before ENISA's EUMSS certification consultation closes. Each is a concrete, sourced development a Swiss/European defender can act on now.2026-07-26NOTABLENATOA2ENISA moved cyber-assurance into procurement leverage this week — a public consultation on a mandatory EU Managed Security Services certification, and concrete hospital-procurement security guidance under a new Health Action PlanTwo ENISA developments inside 2026-W30 turn soft guidance into procurement leverage relevant to the constituency's supplier tail. ENISA opened a public consultation (2026-07-24, open to 2026-09-13) on the draft EU Managed Security Services (EUMSS) certification scheme under the Cybersecurity Act: mandatory baseline requirements across five domains plus a first "vertical" for Incident Response services, and — the consequential part — any provider delivering services under the EU Cybersecurity Reserve must hold EUMSS certification within two years of the scheme's entry into force, turning voluntary certification into a de facto procurement gate. Separately, ENISA signed a EUR 6 million three-year Health Action Plan Contribution Agreement with the European Commission (2026-07-22) and published its first deliverable — updated procurement guidelines for the cybersecurity of hospitals and healthcare providers, giving buyers concrete language for RFPs and vendor contracts. Neither creates a direct Swiss obligation, but both are trackable now for MSSP-selection and healthcare-procurement criteria, and the EUMSS consultation window closes two days after the CRA Article 14 reporting obligation begins on 11 September 2026.2026-07-19NOTABLEexploitedNATOB22026-W29 looking ahead — items already in motion: WordPress WP2Shell and Firefox public exploit code, a SharePoint Pwn2Own chain half-patched until August, a withheld ShareFile CVE, and two EU regulatory clocks runningA justified watch list of items already in motion at the close of 2026-W29 — not predictions. WordPress "WP2Shell" (CVE-2026-63030/-60137) has public PoC on GitHub with NCSC-NL expecting short-term exploitation; Firefox 152.0.6's two critical flaws (CVE-2026-15718/-15719) carry public exploit code with no confirmed in-the-wild abuse yet. Rapid7 is holding the SharePoint JWT auth-bypass CVE-2026-55040 PoC under a 30-day embargo and its chained RCE half is not scheduled for patch until August, so the July fix is the only current break in that chain. Progress has reserved but withheld a ShareFile Storage Zone Controller CVE, due to publish in roughly two weeks. And two EU regulatory clocks are running: the CRA Article 14 reporting obligation from 11 September 2026 and Germany's KRITIS-Dachgesetz registration window opened 17 July. Each is a concrete, sourced development a Swiss/European defender can act on now.2026-07-19NOTABLENATOB2EU critical-entity and product-resilience regulation reached concrete operator-facing milestones this week — ENISA shipped a CRA readiness self-assessment ahead of the 11 September reporting clock, and Germany's KRITIS-Dachgesetz opened its first CER-Directive registration windowTwo EU critical-infrastructure resilience regulatory milestones landed inside 2026-W29, both moving from text to operator action. ENISA published (2026-07-13) a free SME Cyber Resilience Maturity Assessment Model — a diagnostic self-scoring tool across governance, risk management/secure-by-design, vulnerability management, product lifecycle and skills — explicitly timed ahead of the Cyber Resilience Act's first hard clock: from 11 September 2026, CRA Article 14 requires manufacturers of products with digital elements to issue a CSIRT/ENISA early warning within 24 hours of awareness of an actively exploited vulnerability, a fuller notification within 72 hours, and a final report within 14 days. Separately, Germany's KRITIS-Dachgesetz — the national transposition of the EU Critical Entities Resilience (CER) Directive — opened its first operator-registration window on 17 July 2026, requiring ~1,300 identified critical operators across ten sectors to register on a BBK/BSI platform within three months, starting clocks on a risk analysis (nine months) and a resilience plan (ten months). For a Swiss federal SOC both matter through the constituency's supplier and cross-border tail: EU-market suppliers of connected products to Swiss/European public-sector and CI customers are now on the CRA reporting clock, and Swiss organisations with German CI subsidiaries or CER-equivalent reporting relationships are inside the KRITIS-Dachgesetz scope.2026-07-12NOTABLENATOB2Looking ahead — 2026-W28Items already in motion, not predictions: the Dutch NIS2 Cyberbeveiligingswet enters into force 15 August 2026 (five weeks out) and the EU Cyber Resilience Act's 11 September vulnerability/incident-reporting obligation is ~60 days away; FINMA's post-quantum expectation-setting may harden into a binding circular; the Joomla extension file-upload wave's newest members (RSFiles!/Phoca) are patched but not yet exploited, and prior wave members reached CISA KEV within days; Unit 42 references an Expel write-up of The Gentlemen's suspected EDR-disable zero-day that has not yet published; and the STAC3725 initial-access broker continues weaponising CitrixBleed 2 against un-session-terminated NetScaler.2026-06-29NOTABLELooking ahead — 2026-W26ShinyHunters PeopleSoft notifications are still landing — expect more named European education and public-finance victims. GTIG has notified ~100 organisations (68% higher education) and NAIC is the fresh high-profile case; patch internet-reachable PeopleSoft and hunt /PSEMHUB/ and /PSIGW/HttpListeningConnector.2026-06-29NOTABLEEU Cyber Resilience Act — 75 days to the 11 September vulnerability/incident-reporting obligationCRA Article 28 (conformity-body notification) entered force on 11 June 2026; the next binding milestone — mandatory vulnerability/incident reporting by manufacturers to ENISA's Single Reporting Platform — activates 11 September 2026, now ~75 days out (ENISA SRP).2026-06-22NOTABLELooking ahead — 2026-W25RoguePlanet (CVE-2026-50656) has no patch and a PoC that works on June builds — watch MSRC for an out-of-band fix. Microsoft says a fix is "in development" with no timeline; the researcher warns mitigations are not reliable.2026-06-22HIGHG7 Évian cybersecurity declaration calls PQC an "urgent priority" — and the expected hacktivist DDoS materialised on day onePolicy: the G7 called PQC an "urgent priority" and the predicted NoName057(16) DDoS hit Swiss-border Haute-Savoie sites; the CRA's first reporting obligation lands 11 September. (ANSSI, Cyberattaque.org)2026-06-22NOTABLECRA reporting obligation lands 11 September — ENISA Single Reporting Platform access manual due, dry-runs before go-liveThe first Cyber Resilience Act obligation to bind, from 11 September 2026, requires manufacturers of products with digital elements to report actively exploited vulnerabilities (24-hour early warning + 72-hour notification + final report) and severe incidents through ENISA's Single Reporting Platform (EC Digital …2026-06-14NOTABLELooking ahead — 2026-W24G7 Évian summit, 15–17 June — pre-stage DDoS mitigations now. NCSC-CH's advisory explicitly names Swiss organisations as the hacktivist-DDoS target pool for the summit window (Évian sits on the Swiss border), consistent with the NoName057(16) pattern around past Swiss-adjacent summits.2026-06-14NOTABLEENISA publishes the first EU-wide SBOM Adoption State of Play — consumption lags generationENISA released its end-2025 SBOM adoption survey on 9 June — the first EU-wide empirical baseline (ENISA). The report confirms the CRA is the primary accelerant of SBOM adoption and that organisations are investing in SBOM generation and SDLC/CI-CD integration.2026-06-14NOTABLEGermany's Bundestag opens first reading of the CRA domestic-implementation billDrucksache 21/6134 — "zur Durchführung der Verordnung (EU) 2024/2847" — had its first reading on 11 June, designating Germany's national CRA authorities, notified bodies and enforcement routes, with BSI the anticipated primary market-surveillance authority (Deutscher Bundestag).2026-06-10NOTABLEEU Cyber Resilience Act reaches its first hard deadline — notifying-authority designation due 11 JuneUPDATE (originally covered 2026-W23 weekly): 11 June 2026 is the CRA's first mandatory operational milestone: under Chapter IV, member states must have designated the national authority responsible for notifying conformity-assessment bodies (CABs) for higher-risk product classes (European Commission, 2026-06-10).2026-06-01NOTABLELooking ahead — 2026-W23June 10 — Patch Tuesday: Chaotic Eclipse patches expected; researcher promises a "big surprise" the same day. YellowKey (CVE-2026-45585, BitLocker bypass via WinRE autofstx.exe), GreenPlasma (CTFMON SYSTEM escalation), and MiniPlasma (CVE-2020-17103, cldflt.sys Cloud Filter LPE) remain unpatched as of 7 June.2026-06-01NOTABLECRA June 11 notifying-authority deadline — first hard CRA milestone with ENISA SRP manual and Secure Update Mechanisms advisory published11 June is the Cyber Resilience Act's first mandatory milestone: EU member states must designate the national authority responsible for assessing and notifying conformity assessment bodies (CABs) for Important and Critical product classes (OpenSSF policy blog, 2026-06-03; ENISA SRP page).2026-05-25NOTABLEEU Cyber Resilience Act — 11 June notifying-authority deadline, then September reporting obligationsThe Cyber Resilience Act reaches its first hard operational milestones. By 11 June 2026 (Chapter IV entry into application) member states must designate the national notifying authorities that assess and register conformity-assessment bodies for products with digital elements in the "important" and "critical" …2026-05-11NOTABLELooking ahead — 2026-W20Microsoft Exchange CVE-2026-42897 — Microsoft permanent patch and out-of-band advisory on DEVCORE Pwn2Own three-bug chain pending.2026-05-11NOTABLEEU CRA milestones — 11 June 2026 CAB notification, 11 September 2026 Article 14 reporting obligationsTwo CRA enforcement milestones fall within the next 120 days. Chapter IV provisions on notification of Conformity Assessment Bodies (CABs) become applicable on 11 June 2026 — manufacturers seeking CRA conformity certification for critical digital products will be able to use designated CABs from that date, and …2026-05-11NOTABLEVerizon DBIR 2026 (19th annual edition)Verizon's 19th DBIR is publicly accessible on the Verizon DBIR page; the full PDF release is bound to the 2026-05-19 webinar.2026-05-09NOTABLEENISA expands CVE Root: four new European organisations onboarded as CVE Numbering AuthoritiesOn 2026-05-06 ENISA announced four additional organisations joined the CVE Program as CVE Numbering Authorities (CNAs) under ENISA Root, bringing the total under ENISA oversight to at least eleven (ENISA press release, 2026-05-06).2026-05-04NOTABLEEU Cybersecurity Package 2026 — NIS2 amendment (COM(2026) 13) + Cybersecurity Act 2 enter EP preparatory phase; PQC obligation embeddedThe European Commission's 20 January 2026 cybersecurity package bundles a targeted NIS2 amendment (COM(2026) 13) with a new Cybersecurity Act 2 (CSA2). Public-feedback period closed 22 April 2026 — the package is now in the European Parliament preparatory phase, with political agreement targeted for early 2027.2026-05-04NOTABLEENISA expands CVE Numbering Authority root — 4 new CNAs, 7 migrated from MITRE; ~90 European CNAs eligible for transferENISA announced on 2026-05-06 that four organisations have joined the CVE Programme as CVE Numbering Authorities (CNAs) under ENISA Root, and that seven additional European CNAs have migrated from MITRE Root to ENISA Root (ENISA, 2026-05-06).