← Back to all briefings
Policy 5 min read Published Updated Credibility 40/100

Policy Briefing — European Parliament Adopts Cyber Resilience Act Position

The European Parliament approved its negotiating position on the Cyber Resilience Act on 12 September 2023, backing mandatory security requirements and vulnerability handling obligations for connected products.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

On 12 September 2023 Parliament voted to enter trilogues on the Cyber Resilience Act (CRA), a regulation that would impose baseline cybersecurity, vulnerability disclosure, and support lifetime requirements on hardware and software products with digital elements. The Parliament text seeks shorter remediation timelines for critical vulnerabilities and clearer obligations for open-source components used in commercial products.

Manufacturers and software publishers targeting the EU market should monitor the negotiations for final conformity assessment, incident reporting, and secure development mandates. Early alignment of SBOM practices, vulnerability intake processes, and support commitments will ease certification once the CRA is finalized.

Single-point timeline showing the publication date sized by credibility score.
Publication date and credibility emphasis for this briefing. Source data (JSON)

Continue in the Policy pillar

Return to the hub for curated research and deep-dive guides.

Visit pillar hub

Latest guides

  • Cyber Resilience Act
  • Product Security
  • Vulnerability Management
  • European Union
Back to curated briefings