Article 14 is live: three things about ENISA's reporting platform that catch manufacturers out From 11 September 2026 , Article 14 of the EU Cyber Resilience Act applies. If an actively exploited vulnerability turns up in a product you have placed on the EU market, you have 24 hours. Not 24 hou... Sep 14, 2026
A known open-source vulnerability in your product: does the CRA's 24-hour clock start? A new CVE lands against an open-source library that ships inside your product. Article 14 of the EU Cyber Resilience Act has applied since 11 September 2026 . Does the 24-hour reporting clock start? N... Sep 14, 2026
Building automation OEMs are about to meet two regulators at once Building automation sat outside the cybersecurity conversation for a long time, on the argument that a BMS is not a plant. That argument is closing from two directions at once: the EU Cyber Resilience... Sep 5, 2026
CRA Annex I for industrial OEMs: what the essential requirements actually ask of you If you build industrial equipment for the EU market, Annex I is the part of the Cyber Resilience Act you will actually be measured against. It is shorter than its reputation and structured in a way th... Sep 5, 2026
Zones and conduits: the network architecture question 62443 actually asks Ask an OT team about network security and you usually get a product answer a firewall model, a diode, a monitoring appliance. IEC 62443-3-2 asks a different question first, and the products only make ... Sep 5, 2026
IEC 62443-3-3 in practice: seven requirements, four levels, one vector IEC 62443-3-3 is where architecture becomes testable. It takes the zones you drew in 3-2 and states, per zone, what the system has to do. Two things about it are routinely misread, and both cost money... Sep 5, 2026
Where FPGAs and ASICs land under the CRA, and why it decides your route Silicon is one of the few places the Cyber Resilience Act names explicitly, and the naming is finer than most people expect. Three adjacent product descriptions sit in three different tiers, and the t... Sep 5, 2026
IEC 62443, mapped: which part applies to you Most people meet IEC 62443 through a customer questionnaire, open the series, find a dozen documents, and quietly close it again. The series is not hard. It is organised by role , and nobody tells you... Sep 5, 2026
OT cybersecurity is not IT security with different acronyms The fastest way to fail a plant is to arrive with an IT security playbook and apply it literally. The controls are not wrong. The assumptions underneath them are. The priority order is inverted IT sec... Sep 5, 2026
The CRA in December 2027: classification decides how hard your route is The reporting duties that start in September 2026 are the small half of the Cyber Resilience Act. On 11 December 2027 the rest arrives: essential cybersecurity requirements, conformity assessment, tec... Sep 5, 2026
The EU CRA's first deadline is 11 September 2026 - and it covers products you already shipped On 11 September 2026 the EU Cyber Resilience Act starts to bite, and it does so more than a year before most people have it in their plans. If you put products with digital elements on the EU market, ... Sep 4, 2026
The VACK Group, Kashyap Malkan ASQ Live Event - Cybersecurity and QMS We are so excited to be invited to speak at #ASQ event regarding crucial role of #cybersecurity in quality management, how to protect quality and understand the cybersecurity standard #ISO27001 . Malk... #ASQ #ISO27001 cybersecurity Mar 10, 2026