EU critical-entity and product-resilience regulation reached concrete operator-facing milestones this week — ENISA shipped a CRA readiness self-assessment ahead of the 11 September reporting clock, and Germany's KRITIS-Dachgesetz opened its first CER-Directive registration window
The EU's two parallel resilience regimes — the product-side Cyber Resilience Act and the critical-entity-side CER Directive — both produced concrete, operator-facing milestones this week, extending the NIS2-transposition thread the prior two weeklies tracked into the product and physical-resilience tracks.
On the CRA side, ENISA published a free, Excel-based SME Cyber Resilience Maturity Assessment Model letting micro/small/medium manufacturers of products with digital elements self-score readiness across five domains (governance and documentation, risk management and secure-by-design/-by-default, vulnerability management, product lifecycle, and skills), explicit that it is diagnostic and that "reaching a higher maturity level does not replace compliance with the CRA" (ENISA via cyberresilienceact.eu, 2026-07-16; ENISA, 2026-07-13). The timing is the point: from 11 September 2026, CRA Article 14 puts manufacturers on a 24-hour early-warning / 72-hour notification / 14-day final-report clock for actively exploited vulnerabilities in their products.
On the CER side, Germany's KRITIS-Dachgesetz — in force since 17 March 2026 ("Das KRITIS-Dachgesetz ... ist am 17.03.2026 in Kraft getreten," BBK) — opened its first operator-registration window on 17 July 2026 (ChannelPartner, 2026-06-05). Roughly 1,300 identified critical operators across ten sectors must register on a joint BBK/BSI platform within three months, which starts clocks on a risk analysis (nine months) and a documented resilience plan (ten months). Reported fine figures for a registration failure diverge across secondary German trade press (EUR 100,000 vs EUR 500,000) and should be confirmed against the statutory text before being quoted as exact.
reaching a higher maturity level does not replace compliance with the CRA
Das KRITIS-Dachgesetz (kurz: KRITISDachG) ist am 17.03.2026 in Kraft getreten
Sources
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.