Learn the CRA

The Cyber Resilience Act, in plain English.

Short, practical articles on what the CRA is, whether it applies to you, and the terminology you keep running into. New posts regularly. Written by an EU cybersecurity assessor.

Latest articles

Compliance path·7 min read·30 July 2026

When does a change make it a new product?

Ship an update and the question follows: is this still the product you assessed? The Commission's July 2026 guidance finally answers it, and the answer is narrower than most teams fear.

Read
Compliance path·6 min read·30 July 2026

How long must you support it? Five years is not the answer

The five-year figure is a safeguard, not a default. The Commission's guidance is explicit, and getting this wrong is the easiest way to publish a support period that does not comply.

Read
Fundamentals·6 min read·30 July 2026

When your cloud backend is part of the product

Pure SaaS sits outside the CRA. A backend your product cannot work without does not. The Art. 3(2) test has three parts and all three must hold.

Read
Compliance path·5 min read·30 July 2026

One assessment for a range of variants

Six variants of the same product do not need six risk assessments. The Commission's guidance sets out when one covers the group, and the deciding factor is narrower than you might expect.

Read
Fundamentals·5 min read·29 July 2026

The Commission's first CRA guidance, decoded: what it actually answers

On 27 July 2026 the European Commission published its first official guidance on applying the CRA. Here is what it covers, and what to do with it.

Read
Compliance path·4 min read·26 July 2026

What an SBOM is, and why the CRA asks for one

A software bill of materials is an inventory of what is inside your software. Here is what it is, why the CRA wants it, and how to produce one.

Read
Compliance path·4 min read·25 July 2026

What a CRA technical file actually contains

The Annex VII technical file is the evidence behind your Declaration of Conformity. Here is what goes in it, and why it cannot be backfilled.

Read
Compliance path·5 min read·24 July 2026

Self-assessment vs notified body: why most products skip the lab

The CRA lets the majority of manufacturers assess their own products. Here is who can, who cannot, and what self-assessment actually involves.

Read
Deadlines·4 min read·23 July 2026

The two CRA dates that matter: 11 September 2026 and 11 December 2027

One date is a reporting duty on a 24-hour clock. The other is your license to keep selling in the EU. Here is what each means.

Read
Fundamentals·4 min read·22 July 2026

Does the CRA apply to your product? A 60-second test

Three questions decide whether the Cyber Resilience Act covers what you sell. Here they are, with the edge cases that trip people up.

Read
Fundamentals·4 min read·21 July 2026

What the Cyber Resilience Act actually is, in plain English

The CRA in one read: what it covers, who it binds, and the two dates that decide how urgent it is for you.

Read

Terminology

Glossary

CRA glossary: every term, in plain language

CE marking, conformity assessment, technical file, SBOM, notified body, substantial modification, severe incident, and more, each defined in a sentence or two.

Open the glossary