Cyber Regulation Insights

Stay informed about cybersecurity regulations, standards, and compliance requirements across the EU and beyond.

A publication by Secuvi

Latest articles

Security updates under the Cyber Resilience Act

Security updates under the Cyber Resilience Act

The Cyber Resilience Act requires manufacturers to provide and maintain security updates throughout an appropriate support period. That obligation affects product planning, update delivery, technical documentation and supplier management.

Read more →
How EN 18031 evidence can support CRA preparation

How EN 18031 evidence can support CRA preparation

EN 18031 work can provide useful input for Cyber Resilience Act preparation, but it cannot simply be relabelled as CRA conformity evidence. A product-specific risk assessment and a clear view of the final cited standards remain essential.

Read more →
What the Cyber Resilience Act requires you to report

What the Cyber Resilience Act requires you to report

The Cyber Resilience Act does not require manufacturers to report every vulnerability or remediate every CVE immediately. Its early reporting duties begin on 11 September 2026, while broader vulnerability-handling duties generally apply from 11 December 2027.

Read more →
ISO/IEC 27090 for AI system security

ISO/IEC 27090 for AI system security

ISO/IEC 27090 addresses security threats and compromises that are specific to AI systems across their lifecycle. It can help organisations extend established information-security practices with AI-specific risk work.

Read more →
RED delegated act repeal and the transition to the Cyber Resilience Act

RED delegated act repeal and the transition to the Cyber Resilience Act

Commission Delegated Regulation (EU) 2026/339 repeals Commission Delegated Regulation (EU) 2022/30 with effect from 11 December 2027. It preserves RED market surveillance and conformity control for covered radio equipment placed on the Union market between 1 August 2025 and 10 December 2027 that was subject to the relevant requirements.

Read more →
How the new EU Machinery Regulation makes cybersecurity a safety requirement

How the new EU Machinery Regulation makes cybersecurity a safety requirement

The new EU Machinery Regulation coming into force on 20 January 2027 makes cybersecurity a mandatory safety requirement for machinery placed on the European market. This fundamental shift ends the separation between functional safety and IT security, requiring machine builders to integrate cybersecurity into their safety obligations. Learn how this regulatory change will transform machinery design and compliance across Europe.

Read more →
The EN 40000 series explained

The EN 40000 series explained

Discover Europe's groundbreaking EN 40000 cybersecurity standards designed to help manufacturers comply with the new Cyber Resilience Act requirements for digital products. Learn essential implementation strategies for vulnerability handling, threat modelling and security requirements that will impact importers, distributors and product developers across the EU market.

Read more →