Regulatory watch

An unmaintained regulatory reference becomes wrong without warning. This page sets out what is liable to change, where to check it, and what to do when it does.

The three open matters

1. Harmonised standards

Stake: they condition the presumption of conformity and, for class I products, whether self-assessment is possible at all.

Where to track: the work of joint technical committee CEN/CENELEC JTC 13, working group 9, in response to standardisation request M/606; and above all the citation of the references in the Official Journal of the European Union, which alone produces the legal effect.

What changes when a standard is cited: the module A route opens for the class I products covered, subject to full application. The pages Criticality classes, Class I and Conformity assessment must be reviewed, and each affected product’s assessment scenario re-examined.

2. Commission delegated and implementing acts

Stake: they can change scope and detail.

Expected act Effect
Update of Annexes III and IV A product may change class, or enter one
Specification of the SBOM format and elements Your format and level of detail become constrained
Certification requirement for critical product categories A move to EUCC-style assessment
Common specifications An alternative presumption route absent a standard
Simplified technical documentation form for small enterprises A documentation easement

What to do: on each publication, assess the impact on the classification register and on the affected pages, then produce an impact note for the committee.

3. National implementation

Stake: knowing who to address, in which language, through which channel.

Points to track: designation of market surveillance authorities and coordinating CSIRTs by Member States; national penalty regimes; the practical arrangements of ENISA’s single reporting platform; accreditation of notified bodies and the exact scope of their notification in the NANDO database.

What to do: keep up to date, per Member State where your products are made available, the competent authority and the reporting channel.

Sources to follow

Source What it holds Consultation frequency
EUR-Lex — the Regulation Consolidated text, delegated and implementing acts Monthly
Official Journal of the European Union Citation of harmonised standards Monthly
European Commission, CRA page Guidance, FAQ, timeline Monthly
ENISA · EUVD Reporting platform, vulnerability database, technical documents Monthly
CEN / CENELEC JTC 13 Standards progress Quarterly
Notified bodies (NANDO database) Designated bodies and the scope of their notification Quarterly
ANSSI · CERT-FR National implementation, alerts Monthly

What is not a source. Vendor blog posts, commercial white papers, unverified summaries. They contain recurring errors, particularly about criticality classes and the status of open source. Any statement reused internally must be traceable to a published article, annex or act.

The watch process

  1. Monthly review of the sources by the legal department.
  2. Impact note whenever something changes: what the new element says, which pages are affected, what action is required, by when.
  3. Update the affected pages, refreshing their review date.
  4. Quarterly item at the CRA committee: what changed, what you did.
  5. Re-examine the registers for classification and support if the change affects them.

Tagging entries

Every entry in the watch feed carries one or more tags:

  • Legal impact — changes a documentary or contractual obligation
  • Cyber impact — changes a technical requirement or a tool
  • Timeline impact — changes a deadline or a critical path
  • Action required — calls for a decision, as opposed to information only

Site revision log

Date Subject Pages affected
19 August 2026 Initial publication of the reference All

This table is updated at every significant revision. It records what the organisation knew, and since when — useful information in an inspection.