NEW: CRA vulnerability reporting begins 11 September 2026. Is your product ready? Check now →

CRA update, July 2026: ENISA's SME maturity model, and the September clock

ENISA published a free SME maturity model so you can score your CRA readiness, notified bodies are still undesignated, harmonised standards are still not in the Official Journal, and the 11 September reporting deadline is under two months away.

July brought one genuinely useful new tool and three unchanged pressures. If you are preparing for the EU Cyber Resilience Act, here is what moved between mid-June and mid-July 2026, and what to do about it this week.

1. ENISA published a free SME maturity model (13 July 2026)

The headline item. On 13 July, ENISA released the SME Cyber Resilience Maturity Assessment Model, a free, downloadable self-assessment that lets micro, small and medium-sized companies score how ready they are for the CRA.

It rates you from 1 to 5 across five domains:

  • Governance and documentation
  • Risk management and security by design and by default
  • Vulnerability management
  • Product lifecycle management
  • Cybersecurity skills

The scores roll up into an overall profile of basic, intermediate or advanced, and the Excel tool tracks progress across repeated self-checks.

One caveat ENISA is explicit about: reaching a higher maturity level does not replace compliance. The model is a diagnostic, not a conformity assessment. Treat it as a gap-finder that tells you where to spend effort, not as evidence you can hand a notified body.

The tool lands three weeks after ENISA’s SME CRA Survey Report of 24 June, which found that most SMEs know the CRA exists but few have turned that awareness into practical readiness. Incident response and SBOM preparation were the weakest areas.

2. Still zero notified bodies designated

Chapter IV switched on the rules for notified bodies on 11 June, but a month later none have been designated in the Commission’s NANDO database. Member states have until 11 December 2026 to ensure enough capacity exists. See the European Commission’s conformity assessment page for the framework.

If your product is heading for a Class I route without harmonised standards, or any Class II route, notified body capacity is still the binding constraint for the rest of 2026. Get your pre-engagement letters in early; the queue will not get shorter.

3. Harmonised standards are still not in the Official Journal

CEN and CENELEC are still drafting. Per the European Commission’s CRA implementation tracker, the core horizontal standards (secure development, vulnerability handling) are expected around 30 August 2026, with product-specific standards following near 30 October 2026.

This matters because Class I self-assessment is only available once you can fully apply the relevant harmonised standard. Until they are published, that path does not exist in practice, which pushes more products toward notified bodies (see point 2).

4. The reporting clock is under two months away

Vulnerability and incident reporting obligations begin 11 September 2026, and ENISA’s Single Reporting Platform is still in preparation rather than operational. The reporting requirements apply to all in-scope products, including grandfathered ones, so this is the deadline that catches everyone.

You cannot report on components you have not enumerated, which is why an SBOM and a tested reporting runbook need to be in place now, not in September.

What to do this week

  • Run the ENISA SME maturity model to get an honest baseline, then turn the weakest domain into a plan.
  • If you are on a Class I or Class II path, confirm your notified body targets and send pre-engagement letters before Q3 ends.
  • Stand up your Article 14 reporting runbook: identify your main-establishment CSIRT, your SRP contact, and generate an SBOM if you have not already.

Not sure which class you are even in? Our free compliance check walks you through it in a couple of minutes, and the SBOM tutorial covers the artefact you will need for reporting.

Sources

Is Your Product CRA Ready?

Get a free personalised CRA compliance briefing for your specific product type, delivered to your inbox. No spam, no sales calls.

  • Understand your exact product category (default, Class I, or Class II)
  • Get a checklist of your specific obligations and deadlines
  • Receive guidance on SBOM, vulnerability management, and reporting
  • Early access to our CRA Compliance Manager tool (launching 2026)
  • Weekly CRA news digest: ENISA updates, regulatory guidance

Get Your Free CRA Brief

Takes 60 seconds · Completely free

🔒 No spam. Unsubscribe anytime. See our privacy policy.