Global cybersecurity standards and regulatory frameworks are increasingly governing the digital ecosystem, forcing software manufacturers and cloud providers to align technical designs with strict international mandates. Oracle actively participates in more than 100 standards-setting organizations and over 300 technical committees to shape security, cloud, and artificial intelligence regulations worldwide.
Global Regulatory Frameworks Shaping Digital Resilience
Across Europe and the United States, several major legislative acts dictate baseline operational security for digital products. In Europe, these include the Digital Operational Resilience Act (DORA), the Cyber Resilience Act (CRA), the Network and Information Security (NIS2) Directive, and the Cybersecurity Certification Scheme for Cloud Services (EUCS). In the United States, frameworks such as FedRAMP establish security assessment standards for cloud service providers.
Complementing these government mandates, industry organizations like the Open Worldwide Application Security Project (OWASP) develop practical software security resources. Meanwhile, internationally recognized frameworks such as ISO/IEC 27001:2022 provide structural methodologies that organizations use to translate complex government policies into consistent operational workflows.
Oracle Involvement in International Standards Bodies
Because IT, cloud, and AI services operate across international borders, harmonization remains critical for global software delivery. Oracle engages directly with foundational technical bodies to help formulate these benchmarks. The company contributes technical expertise to organizations including the National Institute of Standards and Technology (NIST), ISO/IEC, CEN-CENELEC, and the European Telecommunications Standards Institute (ETSI).

Oracle also participates in open-source and collaborative technology groups such as the Cloud Security Alliance, the Agentic AI Foundation, the Linux Foundation, the Eclipse Foundation, SAFECode, and the Partnership on AI. Within ISO and IEC, Oracle engages with ISO/IEC JTC 1/SC 27, which focuses on information security, cybersecurity, and privacy protection. In Europe, the company contributes to CEN-CENELEC JTC 13, dedicated to cybersecurity and data protection standardization.
The EU Cyber Resilience Act and Harmonized Standards
The European Union Cyber Resilience Act establishes a unified cybersecurity framework for products with digital elements sold within the European market. Under the legislation, manufacturers must meet essential cybersecurity requirements. European harmonized standards provide the primary technical mechanism for companies to demonstrate conformity.
Oracle contributes directly to European standards bodies developing harmonized standards registered by the European Commission. This work includes participation in CEN-CENELEC JTC 13 on standards linked to the CRA, such as the emerging prEN 40000 series. This series addresses core areas including terminology, cyber resilience principles, vulnerability handling, and generic security requirements.

Manufacturers Must Report Actively Exploited Vulnerabilities
The implementation of the Cyber Resilience Act follows a phased schedule. These rules require manufacturers to report actively exploited vulnerabilities and severe security incidents affecting covered products through the European Union framework. This mechanism is designed to support coordinated threat awareness, information sharing, and response across the European cybersecurity ecosystem.
What Is the EU Cyber Resilience Act?
What is the primary purpose of the EU Cyber Resilience Act?
The Cyber Resilience Act introduces a common cybersecurity framework and mandatory security requirements for products with digital elements made available on the European Union market.
Which technical committees develop standards for the Cyber Resilience Act?
CEN-CENELEC JTC 13 develops cybersecurity and data protection standards in Europe, including the emerging prEN 40000 series that covers vulnerability handling and cyber resilience principles.
Keep reading