The Cyber Resilience Act, in plain English.
Short, practical articles on what the CRA is, whether it applies to you, and the terminology you keep running into. New posts regularly. Written by an EU cybersecurity assessor.
Guides
CRA glossaryCRA incident and vulnerability reporting playbook
What to do, hour by hour, when you have to report to the authorities under the CRA. Includes fill-in report templates and a tabletop drill.
Read the guideVulnerability disclosure program (VDP) starter kit
A fill-in-the-blanks kit for a product owner with no security team: a public policy, a security.txt, and the internal process, ready before 11 September 2026.
Read the guideLatest articles
When does a change make it a new product?
Ship an update and the question follows: is this still the product you assessed? The Commission's July 2026 guidance finally answers it, and the answer is narrower than most teams fear.
ReadHow long must you support it? Five years is not the answer
The five-year figure is a safeguard, not a default. The Commission's guidance is explicit, and getting this wrong is the easiest way to publish a support period that does not comply.
ReadWhen your cloud backend is part of the product
Pure SaaS sits outside the CRA. A backend your product cannot work without does not. The Art. 3(2) test has three parts and all three must hold.
ReadOne assessment for a range of variants
Six variants of the same product do not need six risk assessments. The Commission's guidance sets out when one covers the group, and the deciding factor is narrower than you might expect.
ReadThe Commission's first CRA guidance, decoded: what it actually answers
On 27 July 2026 the European Commission published its first official guidance on applying the CRA. Here is what it covers, and what to do with it.
ReadWhat an SBOM is, and why the CRA asks for one
A software bill of materials is an inventory of what is inside your software. Here is what it is, why the CRA wants it, and how to produce one.
ReadWhat a CRA technical file actually contains
The Annex VII technical file is the evidence behind your Declaration of Conformity. Here is what goes in it, and why it cannot be backfilled.
ReadSelf-assessment vs notified body: why most products skip the lab
The CRA lets the majority of manufacturers assess their own products. Here is who can, who cannot, and what self-assessment actually involves.
ReadThe two CRA dates that matter: 11 September 2026 and 11 December 2027
One date is a reporting duty on a 24-hour clock. The other is your license to keep selling in the EU. Here is what each means.
ReadDoes the CRA apply to your product? A 60-second test
Three questions decide whether the Cyber Resilience Act covers what you sell. Here they are, with the edge cases that trip people up.
ReadWhat the Cyber Resilience Act actually is, in plain English
The CRA in one read: what it covers, who it binds, and the two dates that decide how urgent it is for you.
ReadTerminology
CRA glossary: every term, in plain language
CE marking, conformity assessment, technical file, SBOM, notified body, substantial modification, severe incident, and more, each defined in a sentence or two.
Open the glossary