{"id":7639,"date":"2026-03-04T09:15:00","date_gmt":"2026-03-04T09:15:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/04\/02\/post_id-5457\/"},"modified":"2026-07-09T17:19:56","modified_gmt":"2026-07-09T17:19:56","slug":"eu-cyber-resilience-act-from-2026-what-cisos-must-check-when-purchasing-digital-products","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/03\/04\/eu-cyber-resilience-act-from-2026-what-cisos-must-check-when-purchasing-digital-products\/","title":{"rendered":"EU Cyber Resilience Act: CISOs Check Digital Products"},"content":{"rendered":"<p style=\"display:inline-block;background:#69d8ed;color:#fff;padding:4px 14px;border-radius:20px;font-size:0.85em;margin-bottom:18px;\">3 min Reading Time<\/p>\n<p><strong>The EU Cyber Resilience Act (CRA) has been in force since December 10, 2024. Reporting obligations take effect in September 2026, and by December 2027, all digital products on the EU market must meet full security requirements. For CISOs, this changes not only their own compliance landscape but the entire procurement logic: no CE marking without cybersecurity proof, no access to the EU market without a conformity declaration.<\/strong><\/p>\n<h2>TL;DR<\/h2>\n<ul>\n<li>\ud83d\udd12 The CRA is an EU regulation directly applicable in all member states. No national transposition required (unlike NIS2).<\/li>\n<li>\u26a0\ufe0f From September 11, 2026: Mandatory reporting of actively exploited vulnerabilities to ENISA within 24 hours.<\/li>\n<li>\ud83d\udee1\ufe0f From December 11, 2027: Full compliance required. Products without a CRA-compliant CE mark cannot be sold in the EU.<\/li>\n<li>\ud83d\udcca Fines: up to 15 million Euro or 2.5 percent of global annual turnover.<\/li>\n<li>\ud83d\udd27 CISOs need new procurement criteria: conformity declaration, SBOM, support duration, update policy.<\/li>\n<\/ul>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What the CRA Regulates<\/h2>\n<p>The CRA applies to all &#8220;products with digital elements&#8221;  &#8211;  hardware and software placed on the EU market, regardless of whether the manufacturer is based in the EU. An IoT sensor from Shenzhen, a VPN client from California, and a firewall from Munich are all subject to the same rules.<\/p>\n<p>The law distinguishes three classes. Standard products (the majority) can be certified via self-assessment. Class I products (including password managers, VPN tools, web browsers, smart home devices, and operating systems) are subject to stricter procedures. Class II products (firewalls, intrusion detection systems, tamper-proof microprocessors) require third-party assessment by a notified body.<\/p>\n<p>Exemptions include non-commercial open-source software, medical devices, vehicles, and products for national security. Everything else that is digital and commercially distributed falls under the CRA.<\/p>\n<div class=\"evm-stat evm-stat-row\" style=\"display:flex;gap:16px;margin:32px 0;\">\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:20px;font-weight:700;color:#69d8ed;\">Sept. 2026<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Reporting obligations active<\/div>\n<\/div>\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:20px;font-weight:700;color:#69d8ed;\">Dec. 2027<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Full compliance<\/div>\n<\/div>\n<div style=\"flex:1;text-align:center;background:#f0f9fa;border-radius:8px;padding:20px 12px;border-top:3px solid #69d8ed;\">\n<div style=\"font-size:20px;font-weight:700;color:#69d8ed;\">15 Mio. \u20ac<\/div>\n<div style=\"font-size:12px;color:#b8c5ce;margin-top:4px;\">Maximum fine<\/div>\n<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">The Five Core Obligations for Manufacturers<\/h2>\n<p><strong>1. Secure by Design and Default.<\/strong> Cybersecurity must be integrated from the start of development. No weak default passwords, minimized attack surface, encryption of stored and transmitted data. Automatic security updates must be supported.<\/p>\n<p><strong>2. Vulnerability Management and SBOM.<\/strong> Manufacturers must create a Software Bill of Materials (SBOM). Important nuance: publishing the SBOM is not mandatory. It serves internal vulnerability management and must be provided upon request by market surveillance authorities. In addition, a process for coordinated vulnerability disclosure must be established.<\/p>\n<p><strong>3. Reporting Obligations from September 2026.<\/strong> In case of actively exploited vulnerabilities, manufacturers must send an early warning to ENISA within 24 hours. A detailed report must follow within 72 hours, and a final report is due after 14 days.<\/p>\n<p><strong>4. CE Marking for Cybersecurity.<\/strong> No CE marking without CRA compliance. No CE marking, no access to the EU market. Manufacturers must issue an EU Declaration of Conformity. Importers must retain this document for ten years.<\/p>\n<p><strong>5. Minimum of Five Years of Security Updates.<\/strong> Manufacturers must communicate the end-of-support date and provide free security updates throughout the entire support period.<\/p>\n<blockquote style=\"border-left:4px solid #69d8ed;margin:32px 0;padding:20px 24px;background:#fafafa;border-radius:0 8px 8px 0;font-size:1.1em;line-height:1.6;color:#333;\"><p>\n&#8220;The CRA changes the rules of the game for the entire EU digital market. For the first time, cybersecurity becomes a prerequisite for the CE marking of digital products.&#8221;<br \/>\n<cite style=\"display:block;margin-top:12px;font-size:0.8em;color:#888;font-style:normal;\">BSI (Federal Office for Information Security), information page on the Cyber Resilience Act<\/cite>\n<\/p><\/blockquote>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">What CISOs Must Change in Procurement Now<\/h2>\n<p>The CRA binds not only manufacturers but all economic actors along the supply chain. For CISOs and IT procurement, this means procurement criteria need updating.<\/p>\n<p><strong>Seven questions procurement must ask starting in 2026:<\/strong><\/p>\n<p>1. Is there an EU Declaration of Conformity (DoC) for the CRA?<\/p>\n<p>2. Is the CE marking present and related to CRA requirements?<\/p>\n<p>3. How long is the declared support period? What happens at end-of-support?<\/p>\n<p>4. Is an SBOM available (on request)?<\/p>\n<p>5. Which conformity assessment route was chosen?<\/p>\n<p>6. Is there a documented process for coordinated vulnerability disclosure?<\/p>\n<p>7. Does the manufacturer have a policy for automatic security updates?<\/p>\n<p>Procurement contracts should explicitly include CRA conformity proofs, update obligations, and end-of-support agreements. The CRA sets the standard for what constitutes a product defect.<\/p>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Distinctions: CRA, NIS2, DORA, and AI Act<\/h2>\n<p>The CRA regulates <strong>products<\/strong> prior to market authorization. <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/20\/missed-the-nis2-registration-deadline-the-practical-checklist-under-%c2%a7-30-bsig\/\">NIS2<\/a> regulates <strong>organizations<\/strong> during ongoing operations. <a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/post_id-5311\/\">DORA<\/a> regulates <strong>financial institutions<\/strong> and their ICT providers. The AI Act regulates <strong>AI systems<\/strong> by risk class. CRA and NIS2 can apply simultaneously.<\/p>\n<div class=\"evm-stat evm-stat-highlight\" style=\"text-align:center;background:#f0f9fa;border-radius:12px;padding:32px 24px;margin:32px 0;\">\n<div style=\"font-size:48px;font-weight:700;color:#69d8ed;letter-spacing:-0.03em;\">24 h<\/div>\n<div style=\"font-size:15px;color:#444;margin-top:8px;\">Reporting deadline for actively exploited vulnerabilities to ENISA (from Sept. 2026)<\/div>\n<div style=\"font-size:12px;color:#888;margin-top:8px;\">Source: EU Regulation 2024\/2847 (Cyber Resilience Act)<\/div>\n<\/div>\n<h2 style=\"margin-top:64px;margin-bottom:20px;padding-top:16px;\">Conclusion: Cybersecurity Becomes a Market Access Requirement<\/h2>\n<p>The CRA makes cybersecurity the gatekeeper to the EU market. No CE marking without security proof, no marketing without a conformity declaration, no vulnerability without a 24-hour report. Reporting obligations begin as early as September 2026. Anyone waiting until then faces a timing problem.<\/p>\n<h2>Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>Does the CRA apply to software?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. The CRA covers all &#8220;products with digital elements,&#8221; including both hardware and software. Non-commercial open-source software developed without profit motive is exempt.<\/p>\n<\/details>\n<details>\n<summary><strong>Must the SBOM be published?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No. The SBOM must be created and made available upon request by market surveillance authorities. Mandatory public publication is not required.<\/p>\n<\/details>\n<details>\n<summary><strong>What happens in case of non-compliance?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Fines of up to 15 million Euro or 2.5 percent of global annual turnover. In addition, market surveillance authorities may prohibit distribution or order product recalls. In Germany, the BSI (Federal Office for Information Security) is responsible.<\/p>\n<\/details>\n<details>\n<summary><strong>How are CRA and NIS2 related?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">The CRA regulates products (prior to market entry), while NIS2 regulates organizations (during operations). Both can apply simultaneously.<\/p>\n<\/details>\n<details>\n<summary><strong>What must CISOs do by September 2026?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Update procurement criteria, assess existing suppliers for CRA readiness, and amend procurement contracts to include conformity proofs and update obligations.<\/p>\n<\/details>\n<div class=\"evm-styled-box\" style=\"background:#f0f9fa;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<h2 style=\"margin-top:0;margin-bottom:12px;font-size:1.05em;\">Reading Tips from the Editorial Team<\/h2>\n<ul>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/20\/missed-the-nis2-registration-deadline-the-practical-checklist-under-%c2%a7-30-bsig\/\">NIS2 Registration Requirement: Practical Checklist According to \u00a7 30 BSIG<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/post_id-5311\/\">DORA and NIS2 Together: Compliance Double Burden for Financial Services<\/a><\/li>\n<li><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/27\/post_id-5455\/\">Cloud Misconfigurations: The 10 Most Dangerous Security Gaps<\/a><\/li>\n<\/ul>\n<\/div>\n<div style=\"background:#f0f9fa;border-radius:8px;padding:20px 24px;margin:24px 0;border-top:3px solid #69d8ed;\">\n<!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/20\/nis2-registration-requirement\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/nis2-compliance-monitoring-bsig-250x167.jpeg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Missed NIS2 Registration Deadline? Practical Checklist \u00a730 BSIG<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/15\/dora-and-nis2-simultaneously-how-financial-service-providers-manage-the-compliance-double-pressure\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/dora-nis2-gleichzeitig-compliance-doppeldruck-finanzdienstleister-cover-hero-250x143.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">DORA &#038; NIS2: How Financial Firms Manage Compliance Double\u2026<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/02\/27\/cloud-misconfigurations-the-10-most-dangerous-security-gaps-in-aws-and-azure\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/cloud-fehlkonfigurationen-server-rack-250x166.jpeg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Cloud Misconfigurations: Top 10 Security Gaps in AWS and Azure<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/www.digital-chiefs.de\/en\/gartner-it-spending-forecast-april-2026-cio-budget\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-gartner-it-spending-forecast-april-2026-64654886-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Gartner: 13.5% IT Growth by 2026 \u2013 CIOs Must Shift Strategies<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/psd3-in-smes-what-finance-chiefs-must-prepare-for-banking\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-psd3-mittelstand-finanzchefs-banking-api-78939015-250x131.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">PSD3 in SMEs: Preparing Finance Chiefs for Banking APIs<\/span><\/span><\/a><a href=\"https:\/\/www.cloudmagazin.com\/en\/2026\/04\/27\/google-cloud-next-2026-agentic-cloud-roadmap-dach\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-google-cloud-next-2026-agentic-cloud-roa-92019527.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#0bb7fd;margin-bottom:5px;\">cloudmagazin<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Gemini Enterprise Pushes DACH Architects to Overhaul Their Game<\/span><\/span><\/a><a href=\"https:\/\/mybusinessfuture.com\/en\/cybersecurity-boom-why-nis2-is-turning-germanys-security-industry-into-a-growth\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-cybersecurity-boom-nis2-deutschlands-sic-39412011-250x166.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Cybersecurity Boom: NIS2 Drives Germany\u2019s Security Growth<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"The EU Cyber Resilience Act (CRA) has been in force since December 10, 2024. Reporting obligations take effect in September 2026, and by December 2027, all digital products on the EU market must meet full security requirements. For CISOs, this changes not only their own compliance landscape but the entire procurement [&hellip;]","protected":false},"author":10,"featured_media":5484,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"cyber resilience act","_yoast_wpseo_title":"EU Cyber Resilience Act from 2026: What CISOs Must Check When Purchasing Digital","_yoast_wpseo_metadesc":"EU Cyber Resilience Act compliance ensures secure digital products\u2014avoid penalties. Check vendor obligations and certifications now. Act before 2026.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":["post_id-5457"],"footnotes":""},"categories":[259],"tags":[],"class_list":["post-7639","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-strategie-governance-en"],"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":5457,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=7639"}],"version-history":[{"count":8,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7639\/revisions"}],"predecessor-version":[{"id":21751,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/7639\/revisions\/21751"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/5484"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=7639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=7639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=7639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}