<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ce-Marking on Le Site de François</title><link>https://lesitedefrancois.be/en/tags/ce-marking/</link><description>Recent content in Ce-Marking on Le Site de François</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>© 2026 François</copyright><atom:link href="https://lesitedefrancois.be/en/tags/ce-marking/index.xml" rel="self" type="application/rss+xml"/><item><title>EU Cyber Resilience Act (CRA)</title><link>https://lesitedefrancois.be/en/compliance/eu-cra/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://lesitedefrancois.be/en/compliance/eu-cra/</guid><description>&lt;p&gt;The &lt;strong&gt;Cyber Resilience Act (CRA)&lt;/strong&gt; is a European Union regulation — not a voluntary standard — that entered into force on 10 December 2024 and will be fully applicable on 11 December 2027. It is issued by the European Commission and co-legislated by the European Parliament and Council; it is not a certification scheme but a horizontal product-safety law, comparable in structure to the CE-marking directives for physical goods. The CRA applies to &lt;strong&gt;all manufacturers, importers, and distributors&lt;/strong&gt; of &amp;ldquo;products with digital elements&amp;rdquo; — any software or hardware product containing a data connection — that is made available on the EU single market, regardless of where the manufacturer is headquartered. Compliance is &lt;strong&gt;mandatory&lt;/strong&gt;: non-compliant products cannot legally be placed on the EU market after the deadline, and penalties can reach €15 million or 2.5 % of global annual turnover. Key intermediate deadlines include 11 September 2026 (manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours) and 11 June 2026 (conformity assessment body framework becomes operational). Products already on the market before 11 December 2027 are exempt from the full requirements unless they undergo a &amp;ldquo;substantial modification,&amp;rdquo; but they are subject to the vulnerability reporting obligation from September 2026 onward.&lt;/p&gt;</description></item></channel></rss>