← Back

Wire · regulatory

Cyber Resilience Act (CRA) – EU Product Cybersecurity Regulation

Published

8 September 2026

Topic

regulatory

Sectors

AI & ML

Geography

Europe

Source

Read at forkast.news

Verified

Fusion42 · 8 September 2026 · Fusion42 review

The EU's Cyber Resilience Act mandates that manufacturers of connected devices and software must comply with strict cybersecurity requirements, including risk assessments, five-year security updates, and incident reporting via a central platform from September 2026. Non-compliance risks penalties up to €15 million or 2.5% of global turnover.

This Wire brief sits within Fusion42's coverage of AI & ML, and 2 sources have reported it between 7 Sep 2026 and 8 Sep 2026.

◆ The Wire takeaway

Developers of connected devices and AI software must adapt to new binding EU cybersecurity laws with strict incident reporting and long-term update requirements now legally enforced. You need to build compliance processes around the ENISA reporting platform by 2026 or face heavy fines.

Coverage

2 sources · first reported 7 Sep 2026 · latest 8 Sep 2026

Related on Wire

Topics

AI & MLcybersecurityeu-regulationincident-reportingsoftware-securityenisa