
In early June 2026, the European Union Agency for Cybersecurity (ENISA) updated one important document and opened another for public consultation. Both documents are important for implementation of the Cyber Resilience Act (CRA):
- Frequently asked questions about the CRA Single Reporting Platform
The updated FAQ provides valuable information about reporting procedures under Article 14 of the CRA. It includes questions concerning the data fields to be completed as part of a report (FAQ 16), as well as further details on when additional information will become available.
The updated FAQ is available HERE.
- Draft Technical Advisory on Secure Update Mechanisms
This draft opened a public consultation on ENISA’s second technical advisory concerning secure update mechanisms. It is intended to help micro, small and medium-sized manufacturers understand common security threats involved in publishing updates during the product lifecycle and implement practical controls to mitigate risks and ensure secure delivery of updates. The public could comment on the draft until 10 July 2026 using the form published on EUSurvey.
The Draft Technical Advisory on Secure Update Mechanisms is available HERE.