Ampyx Cyber Blog
The Intersection of Regulation & Resilience
The Execution Layer Gap: Why European Critical Infrastructure May Be Looking at the Wrong Regulatory Clock
Many European critical infrastructure operators are planning around December 2027, when the Cyber Resilience Act (CRA) fully applies. Its vulnerability reporting duty under Article 14 took effect on September 11, 2026, and it covers products already deployed in the field. This Foundation report, the first in a six-part series, looks at why regulators are turning to the firmware and bootloader layer below the operating system, how the CRA and the revised Network and Information Security Directive (NIS2) reach it, and what Germany's implementation adds.