Automotive OEMs & Tier-1 Suppliers
Automotive OEMs and Tier-1 suppliers placing connected electronic control units, telematics modules, or in-vehicle infotainment systems on the EU market must comply with the EU Cyber Resilience Act. Article 14 incident reporting applies from 11 September 2026, and the remaining obligations apply from 11 December 2027. Products with safety-critical network interfaces typically fall under Class I, requiring third-party conformity assessment. CVD Portal provides the vulnerability disclosure infrastructure mandated by Article 13.