Cyber Resilience Act: 24 hours to know what is inside your product
From 11 September 2026 actively exploited vulnerabilities must be reported to ENISA within 24 hours, including for products already sold. Without an SBOM you have no data.
The transposition dates to 2024, but real enforcement arrives now. Strip away the noise and six concrete obligations and two dates remain. Here's what the regulation demands of a company with 80 to 500 employees, and what you can ignore.
From 11 September 2026 actively exploited vulnerabilities must be reported to ENISA within 24 hours, including for products already sold. Without an SBOM you have no data.
"Sovereign cloud" is not an adjective: the EU has a yardstick — eight objectives and SEAL levels 0-4 — and in April 2026 it used it on a €180 million tender.
The ability to keep operating no matter what others decide: the Cloud Act, 70% of EU cloud in US hands, and 5 tests to measure it.
Why the contract doesn't protect you, why "datacentre in Europe" isn't enough, and what really changes when the supplier is a US company. No jargon.
Anatomy of a real passive scan: forgotten subdomains, expired certificates, an open RDP port and three keys on GitHub. How it happens and how to close it.
What "AI in production" really means for an SME. Where it pays off, where it doesn't, and why orchestration matters more than the model.
DORA (Reg. EU 2022/2554) demands real digital operational resilience, not paperwork: the 5 pillars, the dates and what a financial SME must actually do.
We state it in the price list, but what does it operationally mean to spin up a SOC for an SME in two days? The diary of a real onboarding. Coming soon on this blog.
The AI Act (Reg. EU 2024/1689) classifies AI by risk: bans, high-risk, transparency. The new dates after the 2026 Omnibus and where an SME should start.
No automated newsletter, no sales sequence. One email when a note worth reading goes out. EU address, one-click unsubscribe.