Ocean Data Systems and the EU Cyber Resilience Act
Ocean Data Systems (ODS) is actively implementing the requirements of Regulation (EU) 2024/2847, the European Union Cyber Resilience Act (CRA), for ODS software products falling within the scope of the Regulation.
Since 11 September 2026, the CRA reporting obligations defined in Article 14 apply to manufacturers of products with digital elements. These obligations include the reporting of actively exploited vulnerabilities and severe incidents having an impact on the security of products.
ODS has established dedicated product-security and vulnerability-management processes covering vulnerability intake, PSIRT assessment, active exploitation assessment, severe-incident evaluation, CRA escalation, remediation follow-up and regulatory reporting.
ODS is also continuing its broader CRA compliance programme in preparation for the full application of the Regulation on 11 December 2027. This work includes cybersecurity risk assessment, secure development practices, vulnerability handling, software component and dependency management, product-security documentation, support-period requirements and applicable conformity-assessment activities.
Our current CRA implementation status and compliance position are described in the official ODS Cyber Resilience Act (CRA) Compliance Status Statement.