Ampyx Cyber Blog

The Intersection of Regulation & Resilience

The Execution Layer Gap: Why European Critical Infrastructure May Be Looking at the Wrong Regulatory Clock
The Execution Layer Gap, Policy Pulse Sandra Weiss The Execution Layer Gap, Policy Pulse Sandra Weiss

The Execution Layer Gap: Why European Critical Infrastructure May Be Looking at the Wrong Regulatory Clock

Many European critical infrastructure operators are planning around December 2027, when the Cyber Resilience Act (CRA) fully applies. Its vulnerability reporting duty under Article 14 took effect on September 11, 2026, and it covers products already deployed in the field. This Foundation report, the first in a six-part series, looks at why regulators are turning to the firmware and bootloader layer below the operating system, how the CRA and the revised Network and Information Security Directive (NIS2) reach it, and what Germany's implementation adds.

Read More