Insights

CRA Insights

Plain-English Cyber Resilience Act explainers and updates, written for the people who have to comply. New entries land here as the rules move.

Generated image
CRA harmonised standards

CRA Harmonised Standards and the Presumption of Conformity: Where Things Stand in 2026

No CRA harmonised standard is cited in the Official Journal yet. Here's what the presumption of conformity means, where M/606's 41 standards stand, how EN 18031 fits, and what to do right now.

Generated image
CRA scope

Is My Product in Scope of the CRA? A Plain-English Guide to "Products with Digital Elements"

The Commission's July 2026 guidance makes CRA scope clearer than ever. Here's how to decide whether your product is a "product with digital elements" - and therefore in scope.

Generated image
CRA reporting obligations

Does This Trigger a CRA Report? How to Identify an Actively Exploited Vulnerability and a Severe Incident Under Article 14

With the 11 September 2026 CRA reporting deadline under 45 days away, here's exactly what triggers a mandatory Article 14 report - and what doesn't.

Editorial, calm and authoritative. Theme: software supply chain and third-party/open-source components inside a product - building blocks, dependency graph, or an SBOM/manifest. Brand colours: deep blue #1C3D6E, gold accent #E0A100, warm off-white #FAF9F6 background. Clean and technical, no fear imagery.
SBOM

CRA and Third-Party Components: You Own the Risk, Even If You Didn't Write the Code

Under the Cyber Resilience Act, you stay responsible for every component in your product - including third-party and open-source software. Here's what Article 13 requires and how to act on it.

Editorial, calm and authoritative. Theme: consumer IoT devices - a connected toy, a smart-home security camera/lock, a health wearable - grouped as regulated 'important' products. Brand colours: deep blue #1C3D6E, gold accent #E0A100, warm off-white #FAF9F6 background. Clean, friendly-tech, not childish, no fear imagery.
Scope

Connected Toys, Smart Locks, and Health Wearables: Why Your Consumer IoT Product Is Probably "Important" Under the CRA

If you make connected toys, smart-home security devices, or health wearables, you are likely in CRA Important Class I - not the default tier. Here is what that means for conformity assessment.

Editorial, calm and authoritative. Theme: putting your own brand/label on a connected product and thereby becoming its legal manufacturer under EU law. Suggest a branded label or nameplate being applied to a connected device, or a CE mark. Brand colours: deep blue #1C3D6E, gold accent #E0A100, warm off-white #FAF9F6 background. No text-heavy clutter, no fear imagery.
Roles

You Put Your Name on It. The CRA Makes You the Manufacturer.

If you sell a connected product under your own name or trademark in the EU, the Cyber Resilience Act treats you as the manufacturer - regardless of who built it. Here's what that means and what to do.

Generated image
Roles

The CRA Authorised Representative (Article 18): What It Is, What It Isn't, and Whether You Need One

Under the Cyber Resilience Act, appointing an EU authorised representative is optional - unlike MDR or RED. Article 18 explained: what the mandate must cover, what it cannot delegate, and why non-EU manufacturers often appoint one anyway.

Generated image
Scope

CRA Transitional Provisions: Do You Have to Re-Certify Products Already on the Market?

Already selling connected products into the EU? Here's exactly what the CRA's transitional provisions mean for legacy inventory - and the one obligation that applies to everyone right now.

Generated image
Vulnerability handling

CRA Annex I, Part II: The Eight Vulnerability-Handling Obligations That Run for Your Product's Entire Life

Annex I, Part II of Regulation (EU) 2024/2847 sets eight ongoing engineering and process obligations that apply from first sale until end of support. Here's what each one means in practice.

Generated image
User documentation

CRA Annex II: The User-Facing Documentation You Must Ship With Your Product

Annex II of the CRA sets out the security information manufacturers must ship with every product. Here's exactly what it requires, how to present it, and how to produce it without reinventing your docs.

Generated image
SMEs and microenterprises

CRA for Small Companies: What Article 33 Actually Gives You

The CRA applies to small companies too - but Article 33 of Regulation (EU) 2024/2847 builds in real relief for microenterprises and SMEs. Here is exactly what you are entitled to.

Generated image
CRA and other EU law

RED Cybersecurity Done - What Does the CRA Add? A Practical Guide for Wireless Product Makers

Already compliant with RED EN 18031? Here's exactly what the CRA adds, what carries over, and what you need to do before December 2027. Plain-English, no fluff.

Generated image
Technical documentation

CRA Technical Documentation: What Annex VII Requires and How to Build Your Technical File

A plain-English guide to the CRA technical file: what Annex VII requires, how it differs from Annex I, the 10-year retention rule, and how to build it now from artefacts you already have.

Generated image
Conformity assessment

CRA Substantial Modification: When Does a Software Update Re-Trigger Your Conformity Assessment?

Not every software update restarts your CRA conformity work. Here's where the line sits, what the Commission's 2026 draft guidance says, and how to build a lightweight gate into your release process.

Generated image
Vulnerability handling

Inside the ENISA Single Reporting Platform: How CRA Vulnerability Reports Actually Flow

The ENISA Single Reporting Platform is the only channel for CRA vulnerability reports from 11 September 2026 - but it isn't live yet. Here's how it works and what to build now.

Editorial cover evoking two EU regulations meeting - the Cyber Resilience Act and the AI Act - as two interlocking shields or overlapping frameworks bridging cybersecurity and AI. Brand navy #1C3D6E with a small gold #E0A100 accent on #FAF9F6. No dense text.
CRA and other EU law

CRA and AI Act: Do You Have to Comply with Both - and Can the Work Be Shared?

If your product has digital elements and contains AI, both the Cyber Resilience Act and the EU AI Act can apply. Here's how the two regimes interact - and how one cybersecurity workstream can serve both.

Editorial cover evoking a compliance checklist and countdown roadmap toward a 2027 deadline. A calm timeline/checklist motif with milestone markers, brand navy #1C3D6E with a small gold #E0A100 accent on #FAF9F6. No dense text.
Getting compliant

Your CRA Compliance Checklist: A Sequenced Readiness Roadmap

A practical, deadline-ordered CRA compliance checklist for manufacturers, importers and distributors. Know what to do first, what can wait, and why September 2026 matters now.

Generated image
Conformity & CE marking

CE Marking and the EU Declaration of Conformity Under the CRA: What You Sign and What Sits Behind It

For most products with digital elements, CE marking under the CRA means one thing: you self-assess, build a technical file, and sign the EU Declaration of Conformity yourself. Here is exactly how that works.

Generated image
Scope

CRA vs NIS2: Which EU Cyber Rule Applies to Your Software - and Is SaaS in or Out?

The CRA covers products placed on the market; NIS2 covers organisations operating essential services. Pure SaaS is generally out of CRA scope - but the line is not always clean.

Support period / security updates theme: a horizontal product lifecycle timeline marked across several years with a recurring update/refresh/shield symbol, conveying "at least five years of free security updates". Brand colours deep navy #1C3D6E and gold accent #E0A100 on warm off-white #FAF9F6. Calm, clean, professional, no fear-mongering, minimal text.
Support period

The CRA Support Period: It's Not a Flat Five Years

The CRA support period is not a flat five-year rule. It's the expected product lifetime - and at least five years. Here's how to set, justify, and communicate yours.

Generated image
Risk assessment

Article 13 CRA Risk Assessment: The Document That Holds Everything Together

Article 13 of the Cyber Resilience Act requires a documented cybersecurity risk assessment before CE marking. Here's what it must cover, why it's load-bearing, and how to build one.

Coordinated vulnerability disclosure theme: a clear reporting channel / inbox or shield with an envelope, conveying a safe "front door" for security researchers to report bugs. Brand colours deep navy #1C3D6E and gold accent #E0A100 on #FAF9F6. Calm, professional, trustworthy, not alarmist.
Vulnerability handling

How to Build a CRA-Compliant Coordinated Vulnerability Disclosure Policy

The CRA requires a CVD policy and a reachable contact point. Here's exactly what to put in it - and how it differs from the mandatory 24h/72h ENISA reporting clock.

Generated image
Penalties

CRA Penalties Explained: The Three Fine Tiers, Who Can't Be Fined, and What Else Authorities Can Do

Article 64 of the Cyber Resilience Act sets three tiers of fines - up to €15M or 2.5% of global turnover at the top. Here's exactly what each tier covers, who is exempt, and what else authorities can do beyond fining.

Generated image
Conformity assessment

CRA Conformity Assessment in 2026: Notified Bodies Are Open, But the Standards Aren't Ready Yet

Chapter IV of the CRA switched on 11 June 2026 - notified bodies can now be designated. But no harmonised standards are published yet. Here's what that gap means for your conformity assessment route.

Generated image
Open source

The CRA and Open Source: What Maintainers, Foundations, and Integrators Actually Need to Know

The EU Cyber Resilience Act treats open source carefully. Individual contributors are generally out of scope. Foundations may be "stewards" with lighter duties. Integrators carry the compliance weight.

Generated image
Roles

The CRA Is Not Just the Manufacturer's Problem: What Importers and Distributors Must Do

Importers and distributors have their own legal duties under the EU Cyber Resilience Act - not just manufacturers. Here's exactly what each role must verify before a product reaches the EU market.

Generated image
Requirements

Security by Design Under the CRA: What Annex I, Part I Actually Requires

Security by design isn't a slogan under the EU Cyber Resilience Act - it's a set of concrete legal requirements in Annex I, Part I. Here's what they mean in practice.

Generated image
Scope

Default, Important or Critical? Find your CRA product class

Your CRA product class decides how you prove compliance. Here is how the default, important (Class I and II) and critical tiers work, with examples.

Generated image
SBOM

Do you need an SBOM for the CRA? A practical starter

The Cyber Resilience Act makes a Software Bill of Materials mandatory. What an SBOM must contain, which format to pick, and how to start generating one this week.

Generated image
Deadlines

What the 11 September 2026 CRA reporting deadline means for you

From 11 September 2026, manufacturers must report actively exploited vulnerabilities and severe incidents to ENISA on a 24h/72h/14-day clock. Here is what changes and how to be ready.