home.social

#cyberresilienceact — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberresilienceact, aggregated by home.social.

  1. Europe is our home. Digital resilience is our mission. 🇪🇺

    Happy #EuropeDay to everyone working to keep the Union secure!

    #CRA #CyberResilienceAct #DigitalEurope

  2. Europe is our home. Digital resilience is our mission. 🇪🇺

    Happy #EuropeDay to everyone working to keep the Union secure!

    #CRA #CyberResilienceAct #DigitalEurope

  3. Europe is our home. Digital resilience is our mission. 🇪🇺

    Happy #EuropeDay to everyone working to keep the Union secure!

    #CRA #CyberResilienceAct #DigitalEurope

  4. Europe is our home. Digital resilience is our mission. 🇪🇺

    Happy #EuropeDay to everyone working to keep the Union secure!

    #CRA #CyberResilienceAct #DigitalEurope

  5. Europe is our home. Digital resilience is our mission. 🇪🇺

    Happy #EuropeDay to everyone working to keep the Union secure!

    #CRA #CyberResilienceAct #DigitalEurope

  6. Everfield Germany to acquire Rhebo, expanding OT cybersecurity footprint across DACH industrial markets

    Everfield Germany GmbH has signed a definitive agreement to acquire Rhebo GmbH. Completion of the transaction remains subject…
    #Germany #DE #Europe #EU #Europa #connectedinfrastructure #cyberresilience #CyberResilienceAct #cybersecurity #Everfield #industrialenvironments #industrialoperator #networkmonitoring #NIS2 #OTsecurity #Rhebo #threatlandscape
    europesays.com/germany/10242/

  7. Cloud tech outages: how the EU plans to bolster its digital infrastructure.

    Global digital infrastructure behind literally every modern service is far more fragile than you’d think…

    The Cyber Resilience Act (CRA), in force since 2024, is the EU’s way of hard wiring “resilience by design” into the entire stack of connected hardware and software that underpins Europe’s digital infrastructure.

    mediafaro.org/article/20260421

    #EU #Cloud #Tech #DigitalSovereignty #CyberResilienceAct

  8. ⁉️ Why does the Cyber Resilience Act still need some tweaking? It’s in the federal government’s coalition agreement 👉 “Digital policy is power politics. We want a digitally sovereign Germany. To achieve this, we will reduce digital dependencies […].“

    And then this: The BSI reporting portal, where approximately 30,000 German companies and government agencies must register as part of the NIS 2 implementation, is based on cloud infrastructure from Amazon Web Services (AWS). 🙉

  9. Heute waren wir bei der Verbändeanhörung im BMI zum CRA-Durchführungsgesetz.

    Wir fordern u.a.:

    1) Unterstützung für Open-Source-Akteure bei der Umsetzung der CRA-Anforderungen!

    2) Das Online-Portal für die CRA-Beschwerdestelle muss auf einer digital souveränen Open-Source-Lösung gebaut werden, keine proprietären US-Hyperscaler in kritischen Bereichen!

    Bei 1) will das BSI eine Übernahme in den Gesetzentwurf prüfen, bei 2) waren sie stur.

    Wir bleiben dran!

    #OpenSource #CyberResilienceAct

  10. Und noch etwas: Wir fordern das BSI auf, für das neu einzurichtende CRA-Beschwerdeportal digital souveräne Open-Source-Lösungen zu verwenden...

    ...statt den gleichen Fehler wie beim NIS-2-Meldeportal zu wiederholen, das sensible Daten der kritischsten Unternehmen in Deutschland verarbeitet und auf einer Cloud-Infrastruktur von AWS aufsetzt. 😵‍💫

    heise.de/meinung/Das-Meldeport

    🔎 Unsere Stellungnahme zum CRA-Durchführungsgesetz findet Ihr hier: osb-alliance.de/pressemitteilu

    #OpenSource #CyberResilienceAct

  11. 📆 Bald müssen Unternehmen die Anforderungen des Cyber Resilience Act (CRA) erfüllen.

    Das deutsche „CRA-Durchführungsgesetz“ legt fest, welche Wirtschaftsakteure bei der CRA-Compliance Unterstützung bekommen können.

    Wir fordern: Das CRA-Durchführungsgesetz muss genau wie der CRA selbst die Besonderheiten des Open-Source-Ökosystems berücksichtigen – denn ohne Open Source läuft nichts!

    🔎 Unsere Stellungnahme findet Ihr hier: osb-alliance.de/pressemitteilu

    #OpenSource #CyberResilienceAct

  12. Stay ahead! Learn how OWASP SAMM helps achieve CRA compliance by turning security requirements into measurable practices, integrating them into your SDLC, and embedding continuous, risk-based security.

    Read: owaspsamm.org/blog/2026/02/27/

    #OWASP #SAMM #CyberResilienceAct #SDLC

  13. Stay ahead! Learn how OWASP SAMM helps achieve CRA compliance by turning security requirements into measurable practices, integrating them into your SDLC, and embedding continuous, risk-based security.

    Read: owaspsamm.org/blog/2026/02/27/

    #OWASP #SAMM #CyberResilienceAct #SDLC

  14. Stay ahead! Learn how OWASP SAMM helps achieve CRA compliance by turning security requirements into measurable practices, integrating them into your SDLC, and embedding continuous, risk-based security.

    Read: owaspsamm.org/blog/2026/02/27/

    #OWASP #SAMM #CyberResilienceAct #SDLC

  15. Stay ahead! Learn how OWASP SAMM helps achieve CRA compliance by turning security requirements into measurable practices, integrating them into your SDLC, and embedding continuous, risk-based security.

    Read: owaspsamm.org/blog/2026/02/27/

    #OWASP #SAMM #CyberResilienceAct #SDLC

  16. Stay ahead! Learn how OWASP SAMM helps achieve CRA compliance by turning security requirements into measurable practices, integrating them into your SDLC, and embedding continuous, risk-based security.

    Read: owaspsamm.org/blog/2026/02/27/

    #OWASP #SAMM #CyberResilienceAct #SDLC

  17. Im Rahmen der Umsetzung des #CyberResilienceAct (CRA) wird uns erneut eine besondere Rolle zuteil. Neben der Ernennung zur marktüberwachenden Behörde übernehmen wir auf europäischer Ebene nun den Vorsitz der Administrative Cooperation Group „AdCo CRA“. 🇪🇺

    Mehr dazu findet ihr in der offiziellen Pressemitteilung: 👉️ bsi.bund.de/dok/1194596

  18. Die EU predigt digitale Souveränität, aber bei der eigenen Konsultation zum #CyberResilienceAct gibt's nur Microsoft-Excel-Formulare. 🤦

    Die #DocumentFoundation kritisiert das als "strukturelle Voreingenommenheit" und fordert offene Standards wie #ODF. Denn wer #LibreOffice nutzt, muss erstmal basteln.

    Sollte die EU nicht mit gutem Beispiel vorangehen? 🌍⚖️

    winfuture.de/news,157339.html

    #FOSS #DigitalSovereignty #EU #OpenStandards

  19. #Digitalization #CyberResilienceAct #EU - Request to the European Commission to adhere to its own guidances - "The European Commission has accepted our request, and starting from today – Friday March 6 – has added the Open Document Format ODS version of the spreadsheet to be used to provide the feedback. We are grateful to the people working at DG CONNECT, the Commission’s Directorate-General for Communications Networks, Content and Technology, for responding to our request within 24 hours. At this point, the rest of this message is no longer relevant, and the call for action is no longer necessary." - The Document Foundation blog.documentfoundation.org/bl

  20. Die Document Foundation wirft der EU-Kommission vor, beim #CyberResilienceAct ausgerechnet auf Microsofts xlsx-Format zu setzen - statt auf offene Standards wie ODF. #LibreOffice winfuture.de/news,157339.html?

  21. La Document Foundation accusa la Commissione Europea di usare esclusivamente il formato proprietario .xlsx per raccogliere feedback sul Cyber Resilience Act, ignorando i propri principi su interoperabilità e standard aperti. #LibreOffice #TDF #CyberResilienceAct #ODF #OpenSource

    linuxeasy.org/la-document-foun

  22. In Brussels 🇪🇺 today, Paul Sharratt is participating in the fourth meeting of the #CyberResilienceAct Expert Group, representing the #SovereignTechAgency in discussions on #CRA implementation.

    Drawing on our experience in the open source ecosystem, we are contributing expertise to help ensure the CRA supports secure and sustainable digital infrastructure in Europe, particularly for maintainers of critical #opensource technologies.

    #FOSS #DigitalInfrastructure #DigitalSovereignty #EU

  23. The European Commission dropped yesterday the new guidance for the Cyber Resilience Act (CRA)! 🇪🇺

    We’ve analyzed the March 2026 updates, focusing on Product with Digital Elements (PDE) interpretation and the new compliance roadmap.

    Full breakdown here:
    🔗 craevidence.com/blog/cra-commi

    #CyberResilienceAct #CRA #CyberSecurity #EU

  24. The @EUCommission published draft guidance on the #CyberResilienceAct, including a detailed chapter on #FOSS. EC staff has worked on these and previous drafts for quite a while, and have been open for concerns/clarification from #opensource community members. If this topic interests you, be sure to have a look. I would be interested to hear your thoughts, I’ll likely write up some feedback.

    ec.europa.eu/info/law/better-r

    Public comment open till March 31st.

  25. The European Commission has published its draft guidance on the #CyberResilienceAct #CRA, including guidelines on provisions about open-source software and remote data processing solutions. 4 weeks to offer feedback!

    ec.europa.eu/info/law/better-r

    #OSS #cybersecurity #law

  26. Our robot runs on NixOS. Here is the problem it actually solves.

    The EU Cyber Resilience Act makes reproducible builds, long-term support, and verifiable SBOMs a legal requirement.
    Our CTRL-OS module runs NVIDIA Jetson on a stock Linux kernel with NixOS. We built a robot on top of it to test real-world integration.
    Next: a Security Tracker for vulnerability exposure on Nix-based stacks.
    We wrote up the full story on our blog:
    cyberus-technology.de/en/artic

    #NixOS #CyberResilienceAct

  27. RE: mastodon.social/@fsfe/11604086

    The deadline for this survey on the Cyber Resilience Act #CRA is on 28 February. This is especially relevant for smaller organisations or individuals involved in #FreeSoftware #OpenSource who will be effected by the #CyberResilienceAct.

  28. Mit dem Cyber Resilience Act zieht die EU die sicherheitspolitische Notbremse für digitale Produkte. Das Bundesamt für Sicherheit in der Informationstechnik erklärt, was das heißt: Security by Design, Update-Pflichten, Meldewege. Klingt selbstverständlich – war es aber nicht. Ab 2027 gilt: Wer vernetzt verkauft, haftet auch für Sicherheit.
    @[email protected]
    #CyberResilienceAct #Cybersicherheit #EU bsi.bund.de/DE/Themen/Unterneh

  29. Hello #EUPolicy community! 👋 #Introduction

    As the Sept 2026 #ENISA deadline nears, the industry is moving from "Policy" to "Practice." 🇪🇺

    At craevidence.com, we help manufacturers, importers, and distributors automate #CyberResilienceAct compliance. Replace manual spreadsheets with:

    🛠️ Practical #CRA documentation
    📦 #SBOM & VEX management
    🇪🇺 #CEmarking evidence

    The 24h reporting window is coming. We provide the automated bridge to ENISA notification. 🤝

    #DigitalEU #Sovereignty #CyberSecurity

  30. Part of a company, foundation or other organisation that does #OpenSource?

    The #EU are seeking feedback to prepare their proposal for "Security Attestations for Open Source", a potential revenue source for Open Source #foundations and Communities!

    We'll share more info on the Commission's proposal soon!

    Give your feedback here ⬇️

    ec.europa.eu/eusurvey/runner/C

    [JM]

    #CRA #CyberResilienceAct

  31. ... um Sicherheitslücken und Stabilitätsprobleme früh sichtbar zu machen.

    Hier unterstützt unsere Schulung „Security Testing mit Fuzzing“!

    Format: 2 Tage Präsenz + Online Session

    Zielgruppe: Teams und Verantwortliche aus Entwicklung, Test und Qualitätssicherung.

    Ort: Fraunhofer FOKUS in Berlin

    Nächste Termine 2026: 05.–06.05., 23.–24.06., 29.–30.09., 24.–25.11.

    👉🏻 fokus-akademie.de/de/kurse/fuz

    #fuzzing #SoftwareTesting #cybersecurity #devsecops #QualityEngineering #CyberResilienceAct

  32. My #FOSDEM2026 talk recordings are up!

    I've been working for the past few months on developing a "theory of voluntary security attestations" -- building on the outlines drawn by #CyberResilienceAct's Article 25, I think there is an opportunity for many #OpenSource projects/communities to become sustainably funded as a result of this new EU cybersecurity regulation.

    Talk #1: 20-minute explainer
    fosdem.org/2026/schedule/event

    Talk #2: 40-minute panel with the public sector
    fosdem.org/2026/schedule/event

    But there are still a lot of unknowns for me, for all of us ...

    So! If you want to get involved, help figure this out, join the Matrix channel -- #oss-attestations:fosdem.org

  33. 📝 Digital Omnibus on AI: the European Parliament Rewrites the Commission's Rules

    Comparative analysis of the IMCO-LIBE Draft Report PE782.530 against the Commission's proposal COM(2025) 836 on the Digital Omnibus on AI: fixed deadlines, AI literacy, sensitive data, sandboxes and...

    🔗 nicfab.eu/en/posts/eup-draft-r

  34. 🌍 💶 Back in December, we looked at the EU’s €1.3B investment in AI, cybersecurity, and digital skills.

    The message still stands: security is no longer optional.

    At RELIANOID, we help organizations embrace secure-by-design solutions, aligned with NIS2, CRA, and EU regulations.

    🔐 Now is the time to invest in security.

    relianoid.com/blog/eu-investme

  35. I once talked about bug bounty platforms and warned the community about them.

    There are deeper issues with these platforms:

    linkedin.com/pulse/transparenc

    Platforms are paid by vendors, so they listen to vendors. A lot of these vendors abuse the platform to silence offensive researchers and the platforms don't care.

    ➡️ My recommendation remains ⬅️

    • contact vendors directly via email
    • use your national CERT for escalations

    If you're in Europe: you're in luck, from 2027 the Cyber Resilience Act (CRA) will make it mandatory to have a responsible disclosure process, so European vendors have to answer to the national CERT (or get fined).

    #PenerationTesting #pentesting #responsibledisclosure #infosec #cybersecurity #CRA #CyberResilienceAct

  36. I once talked about bug bounty platforms and warned the community about them.

    There are deeper issues with these platforms:

    linkedin.com/pulse/transparenc

    Platforms are paid by vendors, so they listen to vendors. A lot of these vendors abuse the platform to silence offensive researchers and the platforms don't care.

    ➡️ My recommendation remains ⬅️

    • contact vendors directly via email
    • use your national CERT for escalations

    If you're in Europe: you're in luck, from 2027 the Cyber Resilience Act (CRA) will make it mandatory to have a responsible disclosure process, so European vendors have to answer to the national CERT (or get fined).

    #PenerationTesting #pentesting #responsibledisclosure #infosec #cybersecurity #CRA #CyberResilienceAct

  37. I once talked about bug bounty platforms and warned the community about them.

    There are deeper issues with these platforms:

    linkedin.com/pulse/transparenc

    Platforms are paid by vendors, so they listen to vendors. A lot of these vendors abuse the platform to silence offensive researchers and the platforms don't care.

    ➡️ My recommendation remains ⬅️

    • contact vendors directly via email
    • use your national CERT for escalations

    If you're in Europe: you're in luck, from 2027 the Cyber Resilience Act (CRA) will make it mandatory to have a responsible disclosure process, so European vendors have to answer to the national CERT (or get fined).

    #PenerationTesting #pentesting #responsibledisclosure #infosec #cybersecurity #CRA #CyberResilienceAct

  38. I once talked about bug bounty platforms and warned the community about them.

    There are deeper issues with these platforms:

    linkedin.com/pulse/transparenc

    Platforms are paid by vendors, so they listen to vendors. A lot of these vendors abuse the platform to silence offensive researchers and the platforms don't care.

    ➡️ My recommendation remains ⬅️

    • contact vendors directly via email
    • use your national CERT for escalations

    If you're in Europe: you're in luck, from 2027 the Cyber Resilience Act (CRA) will make it mandatory to have a responsible disclosure process, so European vendors have to answer to the national CERT (or get fined).

    #PenerationTesting #pentesting #responsibledisclosure #infosec #cybersecurity #CRA #CyberResilienceAct

  39. I once talked about bug bounty platforms and warned the community about them.

    There are deeper issues with these platforms:

    linkedin.com/pulse/transparenc

    Platforms are paid by vendors, so they listen to vendors. A lot of these vendors abuse the platform to silence offensive researchers and the platforms don't care.

    ➡️ My recommendation remains ⬅️

    • contact vendors directly via email
    • use your national CERT for escalations

    If you're in Europe: you're in luck, from 2027 the Cyber Resilience Act (CRA) will make it mandatory to have a responsible disclosure process, so European vendors have to answer to the national CERT (or get fined).

    #PenerationTesting #pentesting #responsibledisclosure #infosec #cybersecurity #CRA #CyberResilienceAct

  40. Want to help shape the future of in Europe?

    Join policymakers, industry leaders, researchers, and community voices at the EU 2026 — in person or online — January 30 in Brussels, Belgium!

    Linux Professional Institute (LPI) is proud to participate in the key event in Europe!

    Learn more: lpi.org/8pnk

    @OpenForumEurope

  41. We've teamed up with @apell, @EclipseFdn, @lfeurope, @mozilla, @OpenForumEurope, and @openssf to bring you the Open Source & EU Policy #devroom at #FOSDEM #FOSDEM26!

    We're bringing together developers, Commission Officials and MEPs to discuss #DigitalSovereignty, Open Source and #Democracy, upcoming #EU policies, solving the EU's problems with #OpenSource, and the #CyberResilienceAct and #Standards.

    We look forward to sharing more about the agenda soon in the comng days!

    [JM]

  42. 📣 #RechtimDFN – neue Folge des Podcast #Weggeforscht ist online!

    🔎Überblick über das europäische #Cybersicherheitsrecht

    In Folge 91 gibt die Forschungsstelle Recht im DFN eine Einführung in das europäische Cybersicherheitsrecht.
    Die wichtigsten europäischen Rechtsakte im Bereich der Cybersicherheit:
    📜 #NIS2Richtlinie
    🛡️ #CyberResilienceAct
    🔐 #CyberSecurityAct

    ➡️ Jetzt reinhören: podcastindex.org/podcast/54391

    @HumboldtUni #UniMuenster #EURecht #ITSicherheit

  43. 📣 #RechtimDFN – neue Folge des Podcast #Weggeforscht ist online!

    🔎Überblick über das europäische #Cybersicherheitsrecht

    In Folge 91 gibt die Forschungsstelle Recht im DFN eine Einführung in das europäische Cybersicherheitsrecht.
    Die wichtigsten europäischen Rechtsakte im Bereich der Cybersicherheit:
    📜 #NIS2Richtlinie
    🛡️ #CyberResilienceAct
    🔐 #CyberSecurityAct

    ➡️ Jetzt reinhören: podcastindex.org/podcast/54391

    @HumboldtUni #UniMuenster #EURecht #ITSicherheit

  44. 📣 #RechtimDFN – neue Folge des Podcast #Weggeforscht ist online!

    🔎Überblick über das europäische #Cybersicherheitsrecht

    In Folge 91 gibt die Forschungsstelle Recht im DFN eine Einführung in das europäische Cybersicherheitsrecht.
    Die wichtigsten europäischen Rechtsakte im Bereich der Cybersicherheit:
    📜 #NIS2Richtlinie
    🛡️ #CyberResilienceAct
    🔐 #CyberSecurityAct

    ➡️ Jetzt reinhören: podcastindex.org/podcast/54391

    @HumboldtUni #UniMuenster #EURecht #ITSicherheit