Compliance Pulse In preparation

What changed in EU security regulation this week.

A weekly, curated digest of EU regulatory and standards changes that matter to secure software delivery. Short, sourced and dated.

What you get

Facts, not advice.

  1. One digest a weekThe Cyber Resilience Act, DORA, NIS2 and the AI Act, plus guidance from ENISA, the European Supervisory Authorities and the European standards bodies.
  2. What changed, and whenEach item states the change, its legislative stage, who it affects and from which date.
  3. Primary sources onlyEvery item links to the official text. Where a summary and the source differ, the source prevails.

Sample item

The Cyber Resilience Act, now reporting.

How an item will look. The facts are real and checked against the Official Journal; the digest itself is not live yet.

Compliance Pulse · Week 41 · 2026Sample

Now applies11 Sep 2026Cyber Resilience Act · Regulation (EU) 2024/2847

CRA vulnerability and incident reporting obligations now apply

Manufacturers must now notify actively exploited vulnerabilities and severe incidents affecting the security of their products, at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform. An early warning is due within 24 hours and a notification within 72 hours; a final report follows.

Affects Manufacturers of products with digital elements on the EU market, including products placed on the market before 11 December 2027 (Article 69(3)).

Source: Article 14, EUR-Lex →

CRA timeline

  1. Published in the Official Journal
  2. Enters into force
  3. Rules on conformity assessment bodies apply
  4. Reporting obligations apply
  5. Applies in full

How an item is made

Drafted with AI. Checked by a person.

  1. Official Journal Regulation (EU)

    An EU act is published

  2. Draft 52/60

    AI drafts a summary of at most 60 words

  3. Source Draft

    An editor checks it against the source

  4. Compliance Pulse Week 41

    The weekly digest goes out

Editorial rules

  • Our own words, with a link to the primary source. Source text is never copied.
  • What changed, its stage, who it affects and from when. Never legal advice.
  • No alarm, no intensifiers, no scores or percentages.
  • Corrections are shown on the item, with a date. Items are never silently rewritten.
  • Summaries are drafted with AI assistance and reviewed and edited by a named editor before publication.

Compliance Pulse reports facts about EU acts and guidance. It is not legal advice, and the official text always prevails.

Launching at pulse.dokimos.me.

Pulse is in preparation. Write to be told when the first digest is out.