OpenSSF rounds up recent European cybersecurity regulatory developments. ENISA updated its FAQ on the Cyber Resilience Act (CRA) Single Reporting Platform, clarifying Article 14 reporting procedures and required data fields. A draft technical advisory on secure update mechanisms is open for public consultation until 10 July 2026, targeting small and medium manufacturers. ENISA also opened a public review of the EUCC Agreed Cryptographic Mechanisms (ACM) draft v3, and published the third edition of the NIS360 report assessing cybersecurity maturity across critical sectors under the NIS2 directive.

2m read timeFrom openssf.org
Post cover image
Table of contents
Updated FAQ on the CRA Single Reporting PlatformDraft Technical Advisory on Secure Update MechanismsENISA public review of EUCC ACM Draft Version 3A new version of the NIS360 report publishedCommission proposes tech sovereignty package
106 Impressions