Knowledge Base → Frameworks & law → 🛡 Security & Resilience Regulation (NIS2 · CRA · DORA · ISO 27001)
🛡 Security & Resilience Regulation (NIS2 · CRA · DORA · ISO 27001)
EU cybersecurity / resilience regulation that intersects data protection, plus ISMS standards. Distinct from the privacy-by-design methodology in SDM & BSI.
Key resources
- NIS2 Directive (EU) 2022/2555
- Cyber Resilience Act (EU) 2024/2847
- DORA — Digital Operational Resilience Act (EU) 2022/2554
- ISO/IEC 27001 (citation — obtain from ISO)
- ENISA — EU Agency for Cybersecurity
See also: SDM & BSI · Breach & Incident Response · Privacy & Security Tools
🆕 Recent additions (auto)
- 2026-09-07 BSI: TR-03183 “Cyber Resilience Requirements” — To implement the requirements of the Cyber Resilience Act (CRA) with binding security requirements for digital products to ensure cybersecurity in the European market, the BSI provides numerous guidance and support. Starting September 11, 2026, manufacturers have a reporting obligation for actively exploited vulnerabilities and severe security incidents. With TR-03183 “Cyber Resilience Requirements,” the BSI aims to provide practical assistance for the fundamentals… (Datenzirkus (BvD))
- 2026-09-07 ENISA: Market for Cybersecurity Assessments 2021–2025 — This new edition of the Report on Market of cybersecurity assessments 2021-2025 aims to provide an overview of the current state of cybersecurity assessment of ICT solutions. To examine the dynamics of the certification market, the report focuses on the development of the number of evaluated solutions. For years, discussions about cybersecurity certification were largely product-centered (Datenzirkus (BvD))
- 2026-09-07 EU: Pay Transparency Directive (ETRL) — The EU Commission has published a FAQ list as part of its information campaign on the ETRL. In parallel, there appear to be expectations within the German federal government that the implementing legislation will be passed soon. While this is also being addressed from the perspective of a works council with respect to the ETRL, the Bundestag has provided information on the implementation options and data protection issues related to the ETRL. 3.6 CRA: Reporting Portal “Single Reporting Platform” (Datenzirkus (BvD))
- 2026-09-07 DAkkS: Start of Accreditation for the Cyber Resilience Act (CRA) — The German Accreditation Body (DAkkS) informs that conformity assessment bodies can now submit applications for accreditation for the Cyber Resilience Act. Even before the implementing legislation is published, the German Accreditation Body (DAkkS) enables conformity assessment bodies (CABs) to apply for accreditation under the Cyber Resilience Act (CRA). Accreditation is a necessary prerequisite for notification under this regulation and is carried out in… (Datenzirkus (BvD))
- 2026-09-07 ENISA: Model for Assessing Cyber Resilience of SMEs under the CRA — The model for assessing cyber resilience of SMEs provides micro-, small and medium-sized enterprises (SMEs) with a structured approach to assessing and strengthening their overall cyber resilience while taking into account the requirements of the Cyber Resilience Act (CRA). The model is primarily aimed at organizations that manufacture and place products with digital elements on the market, as these are directly subject to CRA requirements. However, it can also be used by… (Datenzirkus (BvD))
- 2026-09-07 EU Commission: Guidelines for the Cyber Resilience Act — The EU Commission published new guidelines to support the timely implementation of the Cyber Resilience Act (CRA). The guidelines are based on Article 26 of the CRA (Datenzirkus (BvD))
- 2026-09-07 CRA: Reporting Portal “Single Reporting Platform” — With the Cyber Resilience Act (CRA), a unified reporting platform (Single Reporting Platform – SRP) is being introduced for reporting cybersecurity incidents in the EU’s digital single market. As of September 11, 2026, the corresponding reports must be submitted there (Datenzirkus (BvD))
Curated + auto-enriched.