Policy Briefing — EU Council adopts general approach on Cyber Resilience Act
EU telecom ministers agreed a general approach on the Cyber Resilience Act on 27 June 2023, advancing security requirements for connected products toward trilogue negotiations.
The Council of the EU reached its general approach on the Cyber Resilience Act on 27 June 2023, backing mandatory cybersecurity requirements, vulnerability handling duties, and conformity assessments for hardware and software products with digital elements. The text refines product classifications, clarifies obligations for open-source components used commercially, and updates enforcement timelines ahead of trilogues with Parliament and the Commission.
Product, compliance, and security teams should track their offerings against the CRA’s critical product categories, establish coordinated vulnerability disclosure and SBOM practices, and monitor final negotiations that could tighten default support lifetimes or incident reporting windows.
Continue in the Policy pillar
Return to the hub for curated research and deep-dive guides.
Latest guides
-
Semiconductor Industrial Strategy Policy Guide — Zeph Tech
Coordinate CHIPS and Science Act, EU Chips Act, and Defense Production Act programmes with capital planning, compliance, and supplier readiness.
-
Digital Markets Compliance Guide — Zeph Tech
Implement EU Digital Markets Act, EU Digital Services Act, UK Digital Markets, Competition and Consumers Act, and U.S. Sherman Act requirements with cross-functional operating…
-
Export Controls and Sanctions Policy Guide — Zeph Tech
Integrate U.S. Export Control Reform Act, International Emergency Economic Powers Act, and EU Dual-Use Regulation requirements into trade compliance, engineering, and supplier…




