CRA Insights

Making sense of the EU Cyber Resilience Act

Plain-English, practical articles written from the regulation and security best practice — to help manufacturers understand what the CRA asks and how to meet it.

FOUNDATIONS

What is the EU Cyber Resilience Act?

A plain-English guide to the CRA — what it is, who it applies to, and why it exists.

Read the article →
SCOPE

Is my product in scope of the CRA?

"Products with digital elements," the main exclusions, and a step-by-step way to decide.

Read the article →
TIMELINE

CRA timeline: the key dates

From entry into force to the 2026 reporting duties and full application in December 2027.

Read the article →
REQUIREMENTS

Annex I: the essential requirements, explained

The security-by-design properties and the vulnerability-handling duties, in engineer-friendly terms.

Read the article →
COMPLIANCE JOURNEY

Conformity assessment routes

Self-assessment vs notified body — and how your product's risk class decides.

Read the article →
REQUIREMENTS

SBOMs and the CRA

Why a software bill of materials matters, and how to produce a useful one.

Read the article →
COMPLIANCE JOURNEY

The 24h / 72h / final report

The reporting duties for actively exploited vulnerabilities and severe incidents.

Read the article →
COMPLIANCE JOURNEY

Setting up a CVD policy

How to let researchers report flaws to you responsibly — done once for the whole company.

Read the article →
PRACTICAL

A 90-day readiness plan

A pragmatic, phased plan for a small team to build real CRA momentum.

Read the article →

More articles on the way: CRA risk classes in depth, and how the CRA compares with NIS2 and the RED.