Insights
CRA Insights
Plain-English Cyber Resilience Act explainers and updates, written for the people who have to comply. New entries land here as the rules move.

CRA Harmonised Standards and the Presumption of Conformity: Where Things Stand in 2026
No CRA harmonised standard is cited in the Official Journal yet. Here's what the presumption of conformity means, where M/606's 41 standards stand, how EN 18031 fits, and what to do right now.

Is My Product in Scope of the CRA? A Plain-English Guide to "Products with Digital Elements"
The Commission's July 2026 guidance makes CRA scope clearer than ever. Here's how to decide whether your product is a "product with digital elements" - and therefore in scope.

Does This Trigger a CRA Report? How to Identify an Actively Exploited Vulnerability and a Severe Incident Under Article 14
With the 11 September 2026 CRA reporting deadline under 45 days away, here's exactly what triggers a mandatory Article 14 report - and what doesn't.

CRA and Third-Party Components: You Own the Risk, Even If You Didn't Write the Code
Under the Cyber Resilience Act, you stay responsible for every component in your product - including third-party and open-source software. Here's what Article 13 requires and how to act on it.

Connected Toys, Smart Locks, and Health Wearables: Why Your Consumer IoT Product Is Probably "Important" Under the CRA
If you make connected toys, smart-home security devices, or health wearables, you are likely in CRA Important Class I - not the default tier. Here is what that means for conformity assessment.

You Put Your Name on It. The CRA Makes You the Manufacturer.
If you sell a connected product under your own name or trademark in the EU, the Cyber Resilience Act treats you as the manufacturer - regardless of who built it. Here's what that means and what to do.

The CRA Authorised Representative (Article 18): What It Is, What It Isn't, and Whether You Need One
Under the Cyber Resilience Act, appointing an EU authorised representative is optional - unlike MDR or RED. Article 18 explained: what the mandate must cover, what it cannot delegate, and why non-EU manufacturers often appoint one anyway.

CRA Transitional Provisions: Do You Have to Re-Certify Products Already on the Market?
Already selling connected products into the EU? Here's exactly what the CRA's transitional provisions mean for legacy inventory - and the one obligation that applies to everyone right now.

CRA Annex I, Part II: The Eight Vulnerability-Handling Obligations That Run for Your Product's Entire Life
Annex I, Part II of Regulation (EU) 2024/2847 sets eight ongoing engineering and process obligations that apply from first sale until end of support. Here's what each one means in practice.

CRA Annex II: The User-Facing Documentation You Must Ship With Your Product
Annex II of the CRA sets out the security information manufacturers must ship with every product. Here's exactly what it requires, how to present it, and how to produce it without reinventing your docs.

CRA for Small Companies: What Article 33 Actually Gives You
The CRA applies to small companies too - but Article 33 of Regulation (EU) 2024/2847 builds in real relief for microenterprises and SMEs. Here is exactly what you are entitled to.

RED Cybersecurity Done - What Does the CRA Add? A Practical Guide for Wireless Product Makers
Already compliant with RED EN 18031? Here's exactly what the CRA adds, what carries over, and what you need to do before December 2027. Plain-English, no fluff.

CRA Technical Documentation: What Annex VII Requires and How to Build Your Technical File
A plain-English guide to the CRA technical file: what Annex VII requires, how it differs from Annex I, the 10-year retention rule, and how to build it now from artefacts you already have.

CRA Substantial Modification: When Does a Software Update Re-Trigger Your Conformity Assessment?
Not every software update restarts your CRA conformity work. Here's where the line sits, what the Commission's 2026 draft guidance says, and how to build a lightweight gate into your release process.

Inside the ENISA Single Reporting Platform: How CRA Vulnerability Reports Actually Flow
The ENISA Single Reporting Platform is the only channel for CRA vulnerability reports from 11 September 2026 - but it isn't live yet. Here's how it works and what to build now.

CRA and AI Act: Do You Have to Comply with Both - and Can the Work Be Shared?
If your product has digital elements and contains AI, both the Cyber Resilience Act and the EU AI Act can apply. Here's how the two regimes interact - and how one cybersecurity workstream can serve both.

Your CRA Compliance Checklist: A Sequenced Readiness Roadmap
A practical, deadline-ordered CRA compliance checklist for manufacturers, importers and distributors. Know what to do first, what can wait, and why September 2026 matters now.

CE Marking and the EU Declaration of Conformity Under the CRA: What You Sign and What Sits Behind It
For most products with digital elements, CE marking under the CRA means one thing: you self-assess, build a technical file, and sign the EU Declaration of Conformity yourself. Here is exactly how that works.

CRA vs NIS2: Which EU Cyber Rule Applies to Your Software - and Is SaaS in or Out?
The CRA covers products placed on the market; NIS2 covers organisations operating essential services. Pure SaaS is generally out of CRA scope - but the line is not always clean.

The CRA Support Period: It's Not a Flat Five Years
The CRA support period is not a flat five-year rule. It's the expected product lifetime - and at least five years. Here's how to set, justify, and communicate yours.

Article 13 CRA Risk Assessment: The Document That Holds Everything Together
Article 13 of the Cyber Resilience Act requires a documented cybersecurity risk assessment before CE marking. Here's what it must cover, why it's load-bearing, and how to build one.

How to Build a CRA-Compliant Coordinated Vulnerability Disclosure Policy
The CRA requires a CVD policy and a reachable contact point. Here's exactly what to put in it - and how it differs from the mandatory 24h/72h ENISA reporting clock.

CRA Penalties Explained: The Three Fine Tiers, Who Can't Be Fined, and What Else Authorities Can Do
Article 64 of the Cyber Resilience Act sets three tiers of fines - up to €15M or 2.5% of global turnover at the top. Here's exactly what each tier covers, who is exempt, and what else authorities can do beyond fining.

CRA Conformity Assessment in 2026: Notified Bodies Are Open, But the Standards Aren't Ready Yet
Chapter IV of the CRA switched on 11 June 2026 - notified bodies can now be designated. But no harmonised standards are published yet. Here's what that gap means for your conformity assessment route.

The CRA and Open Source: What Maintainers, Foundations, and Integrators Actually Need to Know
The EU Cyber Resilience Act treats open source carefully. Individual contributors are generally out of scope. Foundations may be "stewards" with lighter duties. Integrators carry the compliance weight.

The CRA Is Not Just the Manufacturer's Problem: What Importers and Distributors Must Do
Importers and distributors have their own legal duties under the EU Cyber Resilience Act - not just manufacturers. Here's exactly what each role must verify before a product reaches the EU market.

Security by Design Under the CRA: What Annex I, Part I Actually Requires
Security by design isn't a slogan under the EU Cyber Resilience Act - it's a set of concrete legal requirements in Annex I, Part I. Here's what they mean in practice.

Default, Important or Critical? Find your CRA product class
Your CRA product class decides how you prove compliance. Here is how the default, important (Class I and II) and critical tiers work, with examples.

Do you need an SBOM for the CRA? A practical starter
The Cyber Resilience Act makes a Software Bill of Materials mandatory. What an SBOM must contain, which format to pick, and how to start generating one this week.

What the 11 September 2026 CRA reporting deadline means for you
From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA on a 24h/72h/14-day clock. Here is what changes and how to be ready.