@adamshostack@infosec.exchange
2026-09-09 22:52 UTC
Appsec roundup - July + August 2026
(New blog post: https://shostack.org/blog/appsec-roundup-july-aug-2026, this is post 1/10)
This end of summer edition leads off with the EU’s release of 83 pages of guidance for the CRA (https://digital-strategy.ec.europa.eu/en/library/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation):
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-09 22:52
Article 26(1) of the CRA requires the Commission to publish guidance to assist economic operators in applying the Regulation, with a particular focus on facilitating compliance by microenterprises and small and medium-sized enterprises (SMEs). Article 26(2) sets out minimum aspects that should be addressed in the guidance. These include: (i) the scope of the CRA (particularly remote data processing solutions and free and open-source software); (ii) the notion of ‘support periods’; (iii) the interplay between the CRA and other EU legislation; and (iv) the concept of ‘substantial modification.’ (2/10)