Dear CRA Network,
Please find below some updates that may be of relevance to the work on the implementation of the CRA, and more in general on cybersecurity.
ENISA FAQs and factsheet on the Single Reporting Platform
In preparation to the entry into application of the
CRA reporting obligations on 11 September 2026, ENISA has updated
its FAQs on the CRA Single Reporting Platform (CRA SRP), including by publishing:
ENISA secure by design and default playbook
ENISA has published its Secure by Design and Default Playbook, a practical guide on the
application of secure by design and default principles throughout the life cycle of a product. The 22 Secure by Design and Secure by Default playbooks are also made available an easy-to-navigate format in a
GitHub repository.
SBOM minimum elements publication
In other cybersecurity news, please note that the U.S. Cybersecurity and Infrastructure Agency (CISA), together with a range of international partners, including 7 Member State cybersecurity agencies (CZ, DE, FR, IT,
NL, PL, SK), have published the
2026 Minimum Elements for a Software Bill of Materials (SBOM). The Directorate-General for Communications Networks, Content and Technology (DG CONNECT) of the European Commission also contributed to this document, in order to cooperate on and emphasise
shared cybersecurity principles. Please note that as this document is a multilateral effort, not all of its elements reflect Union law.
Best wishes,
CRA Team
Have you been forwarded this email? Sign up
here.
You no longer wish to receive these updates? Please reply to this email and we will delete you from our database.