Learn the CRA

The Cyber Resilience Act, in plain English.

Short, practical articles on what the CRA is, whether it applies to you, and the terminology you keep running into. New posts regularly. Written by an EU cybersecurity assessor.

Latest articles

Reporting5 min read5 September 2026

The Single Reporting Platform opens Friday: what to have ready before your first CRA filing

ENISA's SRP is scheduled to go live on 11 September 2026 - the same day the reporting duty starts. Five things to have in place before then, and what to do if the portal stumbles.

Read
Compliance path6 min read30 August 2026

The CE marking: the last thing you affix, not the first

Articles 29 and 30 are two of the shortest in the regulation, and the easiest to get formally wrong. Where the marking goes for hardware and for software, what it may not accompany, and why it is the closing step of conformity rather than a design element.

Read
Compliance path9 min read23 August 2026

Effective and regular tests: what Annex I Part II(3) is actually asking for

One short sentence with no method, no cadence and no standard attached. It is also the requirement that decides whether every other claim in your technical file is an assertion or a finding.

Read
Compliance path10 min read22 August 2026

Shipping a security update: the capability and the channel

Annex I point (2)(c) is the product property and Part II(7) is the process behind it. One limb of (2)(c) does not always apply, and the rest of it always does.

Read
Compliance path8 min read21 August 2026

Availability, and not becoming someone else's problem

Point (2)(h) asks you to keep essential and basic functions running, also after an incident. Point (2)(i) is the only requirement in Annex I Part I that is not about protecting your own user.

Read
Compliance path10 min read20 August 2026

What the product collects, what it records, and what it can be made to forget

Annex I points (2)(g), (2)(l) and (2)(m) are one data lifecycle, and they pull against each other. The logging duty is unconditional, the opt-out is not, and factory reset is usually not erasure.

Read
Compliance path9 min read19 August 2026

Integrity, attack surface and exploitation mitigation: three points, one argument

Annex I points (2)(f), (2)(j) and (2)(k) read as one engineering sequence: make it hard to change what should not change, leave less to attack, and make a successful attack buy less.

Read
Compliance path9 min read18 August 2026

Who gets in, and what they can read

Annex I points (2)(d) and (2)(e) cover access control and confidentiality, including a reporting duty most teams miss and a phrase, state of the art, that no cited standard defines for the CRA yet.

Read
Compliance path10 min read17 August 2026

Secure by default, and the requirement that sits above the list

Annex I point (2)(b) is one sentence carrying three separate duties. Point (1) is the only Part I requirement you cannot mark not applicable. Here is what each asks of a connected device, a firmware image and a piece of software.

Read
Compliance path9 min read7 August 2026

What goes in a CRA technical file: Annex VII part by part, and what satisfies each

The eight parts of the Annex VII technical documentation, with the evidence that satisfies each one and where it comes from inside your business.

Read
Compliance path8 min read6 August 2026

The full CRA Annex III and Annex IV product list, and the four entries people get wrong

Every important and critical product category under the Cyber Resilience Act, quoted from the Official Journal, with the misreadings that change a conformity route.

Read
Deadlines7 min read6 August 2026

The CRA timeline: every date that matters, and the one that already passed

Entry into force, 11 June 2026, 11 September 2026 and 11 December 2027, plus the per-product clocks that run from the day you place a product on the market.

Read
Compliance path6 min read5 August 2026

You need a PSIRT. The CRA just does not call it that

The regulation asks for eight vulnerability-handling duties, a contact address printed in the product documentation, and a clock measured in hours. Nothing part-time survives five years of that.

Read
Compliance path7 min read5 August 2026

Write the evidence once. Four regimes want most of the same file

RED, the CRA, the Machinery Regulation and the US Cyber Trust Mark ask different questions and want largely the same underlying evidence. Here is what actually transfers, and what does not.

Read
Compliance path7 min read30 July 2026

When does a change make it a new product?

Ship an update and the question follows: is this still the product you assessed? The Commission's July 2026 guidance finally answers it, and the answer is narrower than most teams fear.

Read
Compliance path6 min read30 July 2026

How long must you support it? Five years is not the answer

The five-year figure is a safeguard, not a default. The Commission's guidance is explicit, and getting this wrong is the easiest way to publish a support period that does not comply.

Read
Fundamentals6 min read30 July 2026

When your cloud backend is part of the product

Pure SaaS sits outside the CRA. A backend your product cannot work without does not. The Art. 3(2) test has three parts and all three must hold.

Read
Compliance path5 min read30 July 2026

One assessment for a range of variants

Six variants of the same product do not need six risk assessments. The Commission's guidance sets out when one covers the group, and the deciding factor is narrower than you might expect.

Read
Fundamentals5 min read29 July 2026

The Commission's first CRA guidance, decoded: what it actually answers

On 27 July 2026 the European Commission published its first official guidance on applying the CRA. Here is what it covers, and what to do with it.

Read
Compliance path4 min read26 July 2026

What an SBOM is, and why the CRA asks for one

A software bill of materials is an inventory of what is inside your software. Here is what it is, why the CRA wants it, and how to produce one.

Read
Compliance path4 min read25 July 2026

What a CRA technical file actually contains

The Annex VII technical file is the evidence behind your Declaration of Conformity. Here is what goes in it, and why it cannot be backfilled.

Read
Compliance path5 min read24 July 2026

Self-assessment vs notified body: why most products skip the lab

The CRA lets the majority of manufacturers assess their own products. Here is who can, who cannot, and what self-assessment actually involves.

Read
Deadlines4 min read23 July 2026

The two CRA dates that matter: 11 September 2026 and 11 December 2027

One date is a reporting duty on a 24-hour clock. The other is your license to keep selling in the EU. Here is what each means.

Read
Fundamentals4 min read22 July 2026

Does the CRA apply to your product? A 60-second test

Three questions decide whether the Cyber Resilience Act covers what you sell. Here they are, with the edge cases that trip people up.

Read
Fundamentals4 min read21 July 2026

What the Cyber Resilience Act actually is, in plain English

The CRA in one read: what it covers, who it binds, and the two dates that decide how urgent it is for you.

Read

Terminology

Glossary

CRA glossary: every term, in plain language

CE marking, conformity assessment, technical file, SBOM, notified body, substantial modification, severe incident, and more, each defined in a sentence or two.

Open the glossary