惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
B
Blog
博客园 - Franky
H
Help Net Security
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
月光博客
月光博客
云风的 BLOG
云风的 BLOG
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 聂微东
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
M
MIT News - Artificial intelligence
罗磊的独立博客
H
Hackread – Cybersecurity News, Data Breaches, AI and More
宝玉的分享
宝玉的分享
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
V
V2EX
Martin Fowler
Martin Fowler
T
Tailwind CSS Blog
有赞技术团队
有赞技术团队

Element Blog

Making sovereignty standard for European governments Organise your chats your way with Sections We’re interoperable, so you can be sovereign Matrix-based ZaPuK confirmed as a core component within Germany’s Deutschland-Stack Element recognised as a Digital Public Good CompuGroup Medical (CGM) and Element partner to transform healthcare communications Sweden goes live with Matrix-based federation! Air-gapped communications for national security Seamless encrypted history sharing arrives in Element Digital sovereignty is built on an open standard that enables federation Introducing the ESS Community migration tool Spaces has landed on Element X! Meedio partners with Element to deliver sovereign communications across Europe Governments need to adopt Matrix responsibly The Cyber Resilience Act: Implications for open source and digital products Latest Signal and WhatsApp breaches show that consumer apps have no place in government Sustainable decentralised comms at Element Exploring MatrixRTC: Real time communication in rooms The Digital Omnibus: opportunities and risks for open source Element’s multi-tenancy TI-Messenger solution secures ‘Good’ rating in gematik commissioned pentest Open source is key to Europe’s digital sovereignty
Cyber Resilience Act: What changes this week and how Elem...
Denise Almeida · 2026-09-10 · via Element Blog

On 11 September 2026, the first substantive deadline under the Cyber Resilience Act (Regulation (EU) 2024/2847, "the CRA") will come into effect. This Regulation entered into force on 10 December 2024, but it applies in stages, and this week’s date is the second of three stages.

As from 11 September, manufacturers of products with digital elements placed on the EU market become subject to the reporting obligations set out in Article 14. Essentially, an actively exploited vulnerability, or an incident that severely affects the security of a product, now has to be notified to the relevant Computer Security Incident Response Team (CSIRT) and to the European Union Agency for Cybersecurity (ENISA) within a strict timetable:

  1. An early warning, within 24 hours of becoming aware of the incident or actively exploited vulnerability
  2. A more detailed follow-up notification, within 72 hours
  3. A final report once the matter is resolved, within 14 days to 1 month, depending on the type of issue.

This post sets out what this means for Element, why it applies differently depending on which product is involved, and what is still ahead of the CRA’s fuller application in December 2027.

Element as original manufacturer

We have previously discussed the distinction the CRA makes between an open source project without commercial intentions, and the entity that first places a product on the market with commercial intent – the "original manufacturer," in the regulation’s own terminology. 

This distinction is key to understanding what kind of compliance support you might expect to receive from Element when it comes to your own CRA obligations. Element develops and stewards open source software including the Community Edition of the Element Server Suite. On the other hand, where Element packages, sells and supports a product commercially, we are the manufacturer of that product, and take on the CRA’s obligations for it directly. This is the case for Element Server Suite Pro (ESS Pro). 

As a product placed on the market for commercial purposes, ESS Pro sits inside the CRA’s scope in full; the essential requirements in Annex I once those apply from December 2027, and, from this week, the Article 14 reporting timetable for actively exploited vulnerabilities and severe incidents.

Meeting that timetable depends on having a working path from disclosure to notification; a single point where security disclosures are received, an internal escalation route from that inbox to whoever can assess exploitation and severity quickly enough to meet a 24-hour clock, and a defined interface into the CSIRT and ENISA reporting channels themselves.

As a security minded organisation, these requirements are already largely in line with our existing procedures. Much of the groundwork required for CRA compliance is something we have been working towards for a while, embedding best practice into our organisational modus operandi. This includes, but is not limited to, a maintained Software Bill of Materials for ESS Pro, a record of the components it depends on, and change control over the code that ships in it. 

By contrast, Element X and the Community Edition of the Element Server Suite are made available by Element without being placed on the market, and therefore do not come with manufacturer obligations. This is important to consider, and one of the reasons why we do not recommend using ESS Community for professional deployments. We won’t be able to support your organisation’s compliance obligations if you’re not using the Pro products. 

What comes next

This week marks an early milestone, but it’s not the end of the journey. The main obligations (i.e. the essential requirements in Annex I, covering secure-by-design development, documented vulnerability assessment processes and conformity assessments) become enforceable in full from 11 December 2027. 

On our side the work continues towards our CE marking and evaluating the need for third-party certification. Our recommendation to our customers and partners is very simple. Start engaging with the process now, ensure that any changes required are incremental and embedded with your company’s culture, and find trusted suppliers and partners, such as Element, that can help simplify your journey through this and other regulations.