Decoding the world of cybersecurity

ENISA details CRA platform security testing

ENISA has confirmed that AI-based secure-code review formed part of security testing for the EU platform now receiving mandatory Cyber Resilience Act vulnerability and incident reports.

ENISA details CRA platform security testing
Summary
  • AISLE performed AI-based secure-code review during security work on ENISA's Cyber Resilience Act Single Reporting Platform.
  • The platform now receives mandatory reports of actively exploited vulnerabilities and severe product-security incidents.
  • Security of the system is sensitive because manufacturers use it to submit vulnerability and incident information to European authorities.

The infrastructure receiving Europe’s new mandatory product-security reports underwent AI-based secure-code review as part of its security testing, adding new detail about how the EU is protecting a system handling notifications of actively exploited vulnerabilities and severe incidents.

The European Union Agency for Cybersecurity confirmed that AISLE carried out an AI-based secure-code review during development of the Cyber Resilience Act Single Reporting Platform, or SRP.

AISLE said its vulnerability-management process will remain involved in continuous coverage supporting future releases of the platform. ENISA’s Chief Cybersecurity and Operations Officer Hans de Vries separately confirmed in the announcement that the agency had conducted security and user testing with relevant stakeholders, including national computer security incident response teams.

The SRP became operational on 11 September, when the Cyber Resilience Act’s first mandatory reporting obligations took effect for manufacturers. It provides a single electronic mechanism for notifying actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements available in the EU.

Cyber Insider examined the reporting regime before launch in CRA reporting platform enters operational phase. The latest disclosure concerns the security work behind that infrastructure rather than a change to manufacturers’ reporting obligations.

The distinction is important because vulnerability-reporting infrastructure can hold unusually sensitive security information. Notifications may identify products affected by an actively exploited weakness, describe an incident, and provide operational details while investigation or remediation is still under way.

A compromise affecting the confidentiality or integrity of that information could create risks beyond ENISA itself. The CRA therefore assigns the agency responsibility for establishing and managing the SRP and requires appropriate technical and organisational measures to protect submitted information.

ENISA says the platform incorporates security measures intended to preserve confidentiality, while national CSIRTs and other stakeholders were involved in its testing.

AI-assisted code review does not remove the need for conventional assurance. Security of a regulatory platform spans application code, infrastructure, identity and access management, deployment processes, monitoring, change control, and the operational rules governing who can receive and disseminate notifications.

Automated analysis can extend testing coverage, but confidence ultimately depends on how findings are validated and how the wider system is operated after launch.

The trust requirement is particularly acute because the CRA obliges manufacturers to provide information to public authorities on strict timelines. Reporting arrangements depend on companies being able to submit sensitive information without creating an additional exposure around the reporting mechanism itself.

The SRP will also continue to change. ENISA says further functionality will be developed in response to operational experience and user needs. Each addition creates another reason for security assurance to continue after the launch milestone rather than being treated as a one-off exercise.

×