Logo

Your trusted compliance partner

Logo

Your trusted compliance partner

Back To Home

Research Team (Tsaaro)

EU Cyber Resilience Act Reporting Obligations Go Live

The EU Agency for Cybersecurity (ENISA) has deployed the initial operating capability of the Single Reporting Platform (SRP), an online tool developed, operated and maintained by the agency to support manufacturers and open-source software stewards in meeting their reporting obligations under the Cyber Resilience Act (CRA). The platform is designed to allow users to submit information on actively exploited vulnerabilities and severe incidents once and communicate it to the relevant authorities across the EU. 

The launch marks a milestone in the implementation of the CRA, which establishes mandatory cybersecurity requirements for products with digital elements throughout their lifecycle. The CRA’s reporting obligations for manufacturers apply from 11 September 2026, while its main cybersecurity requirements apply from 11 December 2027. ENISA said it will continue improving and expanding the SRP based on operational experience and user needs. 

Under the platform’s coordinated reporting system, a notification is initially received by the designated coordinating Computer Security Incident Response Team (CSIRT), which then disseminates the information to other relevant CSIRTs in Member States where the affected product is available. The notification is also simultaneously made available to ENISA. According to the agency, this approach is intended to help authorities receive information more efficiently, coordinate their response and mitigate cybersecurity risks. 

ENISA said the platform was developed to be functional and user-friendly while meeting security requirements, with measures in place to protect the confidentiality of submitted information. The agency has also provided FAQs, user manuals, tutorial videos, a glossary and a factsheet in different EU languages, alongside a dedicated help desk. From 11 September 2026, manufacturers are required to report actively exploited vulnerabilities and severe incidents affecting the security of products with digital elements; the relevant reporting provision will also apply to open-source software stewards from 11 December 2027 where they are involved in developing such products. 

Source: https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched  

News of the Week 

2. SEBI Proposes Cybersecurity Oversight for Subsidiaries of Market Infrastructure Institutions 

The Securities and Exchange Board of India (SEBI) has proposed extending its IT and Cyber Security Framework for Market Infrastructure Institutions (MIIs) to their subsidiaries, strengthening cybersecurity oversight at the group level. The proposal seeks to bring subsidiaries within a more structured governance framework, with greater emphasis on cybersecurity oversight, accountability and coordinated risk management across entities forming part of an MII group. The approach recognises that cyber risks affecting a subsidiary can potentially create operational and systemic risks for the wider market infrastructure. 

The proposal is particularly significant because stock exchanges, clearing corporations and depositories perform critical functions within India’s securities market. Their technology infrastructure processes and supports large volumes of sensitive financial and transactional information, making resilience against cyber incidents essential to maintaining market continuity. If implemented, the proposed framework would require MIIs to take a broader view of cybersecurity rather than limiting controls to the primary regulated entity. This could increase expectations around group-wide governance, monitoring, risk assessment and accountability for technology and cyber risks. 

Source: SEBI, Consultation Paper on IT and Cyber Security Framework for Market Infrastructure Institutions and their Subsidiaries 

3.CNIL Fines French Hospital €500,000 Over Health Data Security Failures 

France’s data protection authority, the CNIL, has fined Hôpital Privé de la Loire €500,000 following failures concerning the security of personal data. The incident affected data relating to 524,867 patients and 202,246 trusted third parties. The CNIL found shortcomings in the hospital’s security measures, including deficiencies concerning authentication and access controls. Given the sensitive nature of health information, the authority assessed the security measures against the requirements of Article 32 of the GDPR, which requires controllers and processors to implement security measures appropriate to the risks associated with processing personal data. 

The enforcement action highlights the heightened security expectations applicable to organisations processing health data. Healthcare institutions routinely handle medical, identification and administrative information whose unauthorised disclosure can create significant risks for individuals. The decision also demonstrates that GDPR compliance extends beyond having privacy policies and governance documentation. Organisations must implement appropriate technical and organisational measures in practice, particularly where the scale and sensitivity of the data being processed create substantial risks. 

For entities handling special-category data, the case reinforces the importance of robust authentication mechanisms, access management, security monitoring and periodic assessment of technical safeguards. 

Source: https://www.cnil.fr/fr/sanction-hopital-prive-loire  

4. Telangana Tax Department Holds Officers Personally Accountable for Unauthorised AI Sharing of Taxpayer Data 

The Telangana Commercial Taxes Department has issued Circular No. 1/2026 dated 18 August 2026, establishing binding requirements governing the use of artificial intelligence and third-party online platforms by departmental officers. The circular prohibits officers from entering or uploading identifiable taxpayer information into public or commercial AI tools unless expressly authorised. The restricted information includes GSTINs, PANs, names, addresses, bank details, tax returns, invoices, e-way bills and audit or investigation records. 

AI may be used for generic or hypothetical research and drafting, provided that identifiable taxpayer information and case-specific facts are not disclosed. Officers are also required to independently verify AI-generated legal propositions and citations against primary legal sources. Importantly, the circular places personal responsibility on the concerned officer for unauthorised disclosure, including where the act is carried out by a subordinate under the officer’s instructions. It also restricts unauthorised connections between departmental databases and external systems, APIs, browser extensions or personal accounts. 

The directive illustrates how public authorities are beginning to translate broader data-protection and confidentiality obligations into specific controls governing generative AI use by employees, particularly where government databases contain highly sensitive personal and financial information. 

Source: https://cfo.economictimes.indiatimes.com/amp/news/tax-legal-accounting/telangana-tax-dept-holds-officers-personally-accountable-for-unauthorised-ai-sharing-of-taxpayer-data/133994515  

Want to stay ahead? 

Reach out to the experts at Tsaaro today. 

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.

We Help You to Grow Your Business Faster & Easier

Our mission is to redefine Digital Trust — helping businesses stay compliant and secure across data privacy, cybersecurity, AI governance, and risk. With 150+ clients across 6 global regions and 50+ regulations covered, we've partnered with leading brands like Airtel, Adani, Titan, Godrej, Booking.com, Paytm, CRED, Nykaa, IKEA, and Flipkart & more.


  • Specialist Talent, On Demand – Privacy, Cyber, AI & GRC experts via staff augmentation, expert pods, and SME-on-demand.

  • Leadership as a Service – Fractional DPO, CISO, and AI Officer leadership, without the cost of a full-time hire.

  • Proven Results – Trusted by top brands including Adani, CRED, and Flipkart.

  • Responsible AI Governance – Build and run AI programmes aligned to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

  • Cybersecurity Expertise – Protect your business from evolving threats with vCISO-led strategy and assessments.

  • Global Standards & Regulations – Stay ready for GDPR, DPDPA, PDPL, HIPAA, and ISO frameworks across markets.

  • Flexible & Cost-Effective – The right expertise at the right time, without permanent-hiring overhead.

  • Trusted Advisory – Led by certified privacy and security professionals.