Cybersecurity is increasingly shaped not only by technology, but also by the standards and regulatory frameworks that establish common expectations for security across the global digital ecosystem. Examples include the Digital Operational Resilience Act (DORA), the Cyber Resilience Act (CRA), the Network and Information Security (NIS2) Directive and the Cybersecurity Certification Scheme for Cloud Services (EUCS) in Europe, as well as FedRAMP in the United States. Industry initiatives such as the Open Worldwide Application Security Project (OWASP) further contribute to this ecosystem by advancing practical approaches and resources for software security.  

As governments introduce new cybersecurity requirements and organizations navigate an increasingly complex threat landscape, internationally recognized standards such as ISO/IEC 27001:2022 can play an important role in translating policy objectives into practical and consistent approaches to security. International harmonization of standards is especially relevant for Oracle as we provide our products and services worldwide, and IT, AI and cloud products and services are most efficiently provided for a global market. 

At Oracle, participation in standards development has long been part of how we build, innovate, and engage with the broader technology ecosystem. Oracle participates actively in more than 100 standards-setting organizations and more than 300 technical committees, with thousands of employees engaged in standards or open source projects. 

Learn more about this work at Standards at Oracle. 

Helping shape the security standards landscape 

Oracle engages across the global cybersecurity standards landscape, contributing to work spanning security and AI governance, cloud security, secure software development, and emerging regulatory requirements. 

This includes participation in organizations and initiatives such as NIST, ISO/IEC, CEN-CENELEC, ETSI, Cloud Security Alliance, Agentic AI Foundation,  OWASP, Linux Foundation, Eclipse Foundation, SAFECode and Partnership on AI. 

Oracle also participates in the development of foundational cybersecurity standards through organizations including ISO/IEC JTC 1/SC 27, focused on information security, cybersecurity, and privacy protection, ETSI and CEN-CENELEC JTC 13, focused on cybersecurity and data protection standardization in Europe. 

The Security section of Standards at Oracle provides a broader view of Oracle’s work across these areas. Oracle is a leader in the key security standards landscape, not only participating but actively driving and influencing the future of security. By contributing ideas and participating in the development of standards, Oracle can move forward the standards that will support legislation and provide a more secure world.  

The EU Cyber Resilience Act: where standards and regulation meet 

The EU Cyber Resilience Act reflects a broader trend: cybersecurity regulation and technical standardization are becoming increasingly interconnected. It provides an important example of the relationship between cybersecurity legislation and technical standards. 

The CRA introduces a common cybersecurity framework for products with digital elements made available on the European Union market. The Act establishes essential cybersecurity requirements, with European harmonized standards expected to provide important technical mechanisms for demonstrating conformity with applicable requirements.  

Oracle participates in European standards bodies involved in developing harmonized standards supporting implementation of the CRA which have been registered by the European Commission. The Security section of Standards at Oracle highlights work within CEN-CENELEC JTC 13 on standards related to the CRA, including the emerging prEN 40000 series addressing areas such as vocabulary, principles for cyber resilience, vulnerability handling, and generic security requirements.   

Participation in standards development enables Oracle to contribute technical expertise and industry perspectives as cybersecurity requirements evolve. It also provides an opportunity to help develop standards that can translate legal requirements into practical, technically meaningful requirements. Last but not least, participating in standards development helps Oracle to meet our customer needs and requirements, ensuring that we deliver safe and secure products and services. 

Preparing for the Cyber Resilience Act 

The CRA introduces requirements in phases, as outlined in a previous Oracle blogpost. 

On September 11, 2026, the CRA’s vulnerability and incident reporting obligations became applicable. These obligations require manufacturers to report actively exploited vulnerabilities and severe security incidents affecting covered products through the European Union’s reporting framework, supporting coordinated awareness, information sharing, and response across the EU cybersecurity ecosystem. More information about the reporting requirements is available from the European Commission and the European Union Agency for Cybersecurity (ENISA).   

Oracle’s preparations for these requirements build on established vulnerability management and security incident response capabilities. Oracle continues to evolve its approach, including through automation designed to help accelerate vulnerability detection and response, helping to identify, assess, prioritize, and respond to vulnerabilities more efficiently.  

Beginning on December 11, 2027, the CRA’s broader product cybersecurity requirements become applicable. These requirements establish cybersecurity and vulnerability management obligations across the product lifecycle for products with digital elements. Cloud computing services are generally addressed separately under the EU’s NIS2 Directive framework, which sets cybersecurity risk-management requirements for cloud service providers. 

Oracle continues to assess and prepare for applicable CRA requirements in line with evolving implementation guidance and supporting standards. This includes identifying Oracle products within the scope of the CRA, assessing them against applicable essential cybersecurity requirements, evaluating relevant third-party supply chain considerations, and preparing for applicable conformity assessment and declaration requirements. 

This work builds on established Oracle security practices, including Oracle Software Security Assurance (OSSA), Oracle’s methodology for incorporating security into the design, build, testing, and maintenance of its products. OSSA includes security training for development organizations, security analysis and testing, and vulnerability disclosure and remediation practices. Oracle’s Information Security Incident Response capabilities further support preparations for the CRA’s reporting obligations. 

Conclusion 

As cybersecurity technologies, threats, standards, and regulations continue to evolve, Oracle will continue engaging with standards organizations, industry partners, policymakers, and the broader security community. Oracle participates in the European standards bodies that have been tasked with establishing harmonized standards for the CRA. 

Oracle’s role in cybersecurity standardization goes beyond following standards after they are published. By contributing ideas, technical expertise, and real-world experience to standards development, Oracle can help advance standards that are technically sound, practical to implement, responsive to customer needs, and capable of supporting a more secure digital ecosystem. 

Through this engagement, Oracle can help move forward standards that support legislation, strengthen cyber resilience, and contribute to a more secure Europe and global digital ecosystem. 

Well-developed standards can help translate high-level regulatory objectives into repeatable technical practices. They can promote consistency, interoperability, and common approaches to security while helping reduce fragmentation across markets. That is why active participation matters. 

Learn more