Regulatory watch
An unmaintained regulatory reference becomes wrong without warning. This page sets out what is liable to change, where to check it, and what to do when it does.
The three open matters
1. Harmonised standards
Stake: they condition the presumption of conformity and, for class I products, whether self-assessment is possible at all.
Where to track: the work of joint technical committee CEN/CENELEC JTC 13, working group 9, in response to standardisation request M/606; and above all the citation of the references in the Official Journal of the European Union, which alone produces the legal effect.
What changes when a standard is cited: the module A route opens for the class I products covered, subject to full application. The pages Criticality classes, Class I and Conformity assessment must be reviewed, and each affected product’s assessment scenario re-examined.
2. Commission delegated and implementing acts
Stake: they can change scope and detail.
| Expected act | Effect |
|---|---|
| Update of Annexes III and IV | A product may change class, or enter one |
| Specification of the SBOM format and elements | Your format and level of detail become constrained |
| Certification requirement for critical product categories | A move to EUCC-style assessment |
| Common specifications | An alternative presumption route absent a standard |
| Simplified technical documentation form for small enterprises | A documentation easement |
What to do: on each publication, assess the impact on the classification register and on the affected pages, then produce an impact note for the committee.
3. National implementation
Stake: knowing who to address, in which language, through which channel.
Points to track: designation of market surveillance authorities and coordinating CSIRTs by Member States; national penalty regimes; the practical arrangements of ENISA’s single reporting platform; accreditation of notified bodies and the exact scope of their notification in the NANDO database.
What to do: keep up to date, per Member State where your products are made available, the competent authority and the reporting channel.
Sources to follow
| Source | What it holds | Consultation frequency |
|---|---|---|
| EUR-Lex — the Regulation | Consolidated text, delegated and implementing acts | Monthly |
| Official Journal of the European Union | Citation of harmonised standards | Monthly |
| European Commission, CRA page | Guidance, FAQ, timeline | Monthly |
| ENISA · EUVD | Reporting platform, vulnerability database, technical documents | Monthly |
| CEN / CENELEC JTC 13 | Standards progress | Quarterly |
| Notified bodies (NANDO database) | Designated bodies and the scope of their notification | Quarterly |
| ANSSI · CERT-FR | National implementation, alerts | Monthly |
What is not a source. Vendor blog posts, commercial white papers, unverified summaries. They contain recurring errors, particularly about criticality classes and the status of open source. Any statement reused internally must be traceable to a published article, annex or act.
The watch process
- Monthly review of the sources by the legal department.
- Impact note whenever something changes: what the new element says, which pages are affected, what action is required, by when.
- Update the affected pages, refreshing their review date.
- Quarterly item at the CRA committee: what changed, what you did.
- Re-examine the registers for classification and support if the change affects them.
Tagging entries
Every entry in the watch feed carries one or more tags:
- Legal impact — changes a documentary or contractual obligation
- Cyber impact — changes a technical requirement or a tool
- Timeline impact — changes a deadline or a critical path
- Action required — calls for a decision, as opposed to information only
Site revision log
| Date | Subject | Pages affected |
|---|---|---|
| 19 August 2026 | Initial publication of the reference | All |
This table is updated at every significant revision. It records what the organisation knew, and since when — useful information in an inspection.