All Topics

Subscribe
Article
Ready, respond, report: the Cyber Resilience Act’s reporting regime is here
The EU's Cyber Resilience Act introduces mandatory vulnerability and incident reporting obligations for manufacturers of digital products starting 11 September 2026, well before the broader regulatory framework takes effect. Manufacturers must navigate tight reporting deadlines, determine when they become "aware" of security events, and establish governance structures to comply with 24-hour early warnings and subsequent detailed notifications through a platform that is not yet operational.
Afghanistan Technology
CMS Wistrand
Article
ECHA Will Hold Webinars To Assist SMEs In Navigating Chemical Regulations
The European Chemicals Agency is launching two specialized webinars in 2026 to help micro, small, and medium-sized enterprises navigate complex chemical regulatory requirements. These sessions will cover poison centre notification procedures and the process for applying for reduced regulatory fees, reflecting ECHA's enhanced commitment to supporting smaller businesses in meeting their compliance obligations.
European Union Government
BC
Bergeson & Campbell
Article
FinXP Partners With Thredd To Strengthen Multi-Region Card Issuing Capabilities
FinXP, a European payment infrastructure provider, has joined forces with Thredd, a global issuer-processing platform, to enhance its card issuing capabilities and expand its embedded finance offering. The partnership will enable FinXP to modernize its debit card programmes with advanced processing infrastructure while maintaining control of its own ledger and programme strategy. This collaboration also positions FinXP as a European BIN sponsor for Thredd's global client base, supporting scalable, multi-reg
Afghanistan Finance
FM
Finance Malta
Article
EU Cyber Resilience Act's New Vulnerability And Incident Reporting Requirements For Products With Digital Elements Entered Into Force
Starting September 11, 2026, manufacturers of digital products in the EU must report cybersecurity vulnerabilities and incidents within strict 24-hour and 72-hour deadlines under the new Cyber Resilience Act. Companies face penalties up to €15 million or 2.5% of global turnover for non-compliance, requiring immediate preparation of incident response procedures and assessment of product portfolios to meet these unprecedented product-focused cybersecurity obligations.
European Union Strategy
S
Steptoe LLP
See more