Skip to main content

Changelog

What changed in the workspace, newest first, and the version of the rulebook it runs on.

Releases

Dated entries for the product. Regulatory content changes are recorded separately below, because a legal source refreshed is a different kind of change from a feature shipped.

  1. Launch preview

    First public preview of the workspace: a product registry with a per-product scope wizard that records its reasoning, an obligations checklist generated from the regulatory catalogue, the Article 14 reporting desk with the 24-hour, 72-hour and final-report clocks and the Single Reporting Platform field list, public trust pages with security.txt, SBOM uploads in CycloneDX and SPDX, and billing in euro or US dollars. Alongside it, the public site gains pricing, guides, a security page and the legal pages.

    • Product registry
    • Scope wizard
    • Obligations
    • Article 14 desk
    • Trust pages
    • SBOM uploads
    • Billing
  2. Regulatory content catalogues 1.0.0

    The rulebook the workspace runs on, kept as versioned data with a source URL and retrieval date for every item: manufacturer obligations from Articles 13 and 14 and Annexes I, II, V, VI, VII and VIII; the scope decision tree derived from the Commission FAQ v1.4; the Annex III and IV categories with the technical descriptions of Implementing Regulation (EU) 2025/2392; the CSIRT coordinator list; the Single Reporting Platform field model; and the key dates of the Regulation.

    • Rulebook

Rulebook

The regulatory content the workspace runs on is versioned data with a source and a retrieval date for every item. The obligations catalogue is at version 1.0.0, with sources retrieved on 23 September 2026.

  • Obligations

    Manufacturer obligations under the Cyber Resilience Act (Regulation (EU) 2024/2847): Articles 13 and 14 and Annexes I, II, V, VI, VII and VIII, with applicability rules and evidence hints.

    Version 1.0.0; 38 sources, retrieved 23 September 2026.

  • Scope rules

    Scope wizard decision tree: is a product a product with digital elements in scope of the Cyber Resilience Act?

    Version 1.0.0; 12 sources, retrieved 23 September 2026.

  • Product classes

    Important (Annex III class I and II) and critical (Annex IV) product categories with the Implementing Regulation (EU) 2025/2392 technical descriptions and the applicable conformity assessment routes.

    Version 1.0.0; 5 sources, retrieved 23 September 2026.

  • CSIRT coordinators

    CSIRTs designated as coordinators under the Cyber Resilience Act, from ENISA's list of 10 September 2026, with contact details from each CSIRT's own website.

    Version 1.0.0; 23 sources, retrieved 23 September 2026.

  • Single Reporting Platform fields

    Single Reporting Platform field model per case type and reporting stage, transcribed from the ENISA CRA SRP Glossary v1.3 (10 September 2026) and Article 14(2) and (4).

    Version 1.0.0; 4 sources, retrieved 23 September 2026.

  • Key dates

    Key dates of the Cyber Resilience Act (entry into force, staged application, transitional provisions) and the status of harmonised standards.

    Version 1.0.0; 16 sources, retrieved 23 September 2026.

A catalogue version changes whenever a legal source is refreshed or an item is added, and the obligations shown in every workspace cite it. The Commission guidance C(2026) 5252 of 27 July 2026 is referenced by the catalogues but not yet ingested.