4 ms·
You should look for security frameworks based on this law. A common example is SOC2; the compliance audit has you compiling documents and recording SLAs long be
by samuelknight 1mo ago
You should look for security frameworks based on this law. A common example is SOC2; the compliance audit has you compiling documents and recording SLAs long before any security incident might require it. There are many open source tools that you can use to track compliance in the various frameworks on your own. One of them may have an update for this new law.
- dirkk0 1mo agoThanks. The CRA's own version of what you are describing is harmonised standards: Art. 27 gives you a presumption of conformity with the Annex I requirements if you follow one whose reference has been published in the Official Journal. The catch is that they do not exist yet. M/606 covers around 41 standards and was accepted by CEN, CENELEC and ETSI in 2025, but the Commission's July 2026 draft amendment pushed the deadlines back two months: the two core horizontal standards (secure development, vulnerability handling) are now due 31 October 2026, the verticals 31 December 2026, and the remaining horizontal ones October 2027, about a year before full application. And delivery is not the same as availability - a standard only gives you the Art. 27 presumption once its reference is cited in the Official Journal. Nothing has been cited for the CRA yet: the Commission's harmonised standards site lists 40 pieces of legislation and the CRA is not among them. On tooling specifically: the Open Regulatory Compliance Working Group (orcwg.org) runs a CRA hub on GitHub, closest thing I have found to what you describe. I wish it were less complicated. :)