The Cyber Resilience Act, in plain English.
Short, practical articles on what the CRA is, whether it applies to you, and the terminology you keep running into. New posts regularly. Written by an EU cybersecurity assessor.
Guides
CRA glossaryCRA incident and vulnerability reporting playbook
What to do, hour by hour, when you have to report to the authorities under the CRA. Includes fill-in report templates and a tabletop drill.
Read the guideVulnerability disclosure program (VDP) starter kit
A fill-in-the-blanks kit for a product owner with no security team: a public policy, a security.txt, and the internal process, for a reporting duty that already applies.
Read the guideLatest articles
The Single Reporting Platform opens Friday: what to have ready before your first CRA filing
ENISA's SRP is scheduled to go live on 11 September 2026 - the same day the reporting duty starts. Five things to have in place before then, and what to do if the portal stumbles.
ReadThe CE marking: the last thing you affix, not the first
Articles 29 and 30 are two of the shortest in the regulation, and the easiest to get formally wrong. Where the marking goes for hardware and for software, what it may not accompany, and why it is the closing step of conformity rather than a design element.
ReadEffective and regular tests: what Annex I Part II(3) is actually asking for
One short sentence with no method, no cadence and no standard attached. It is also the requirement that decides whether every other claim in your technical file is an assertion or a finding.
ReadShipping a security update: the capability and the channel
Annex I point (2)(c) is the product property and Part II(7) is the process behind it. One limb of (2)(c) does not always apply, and the rest of it always does.
ReadAvailability, and not becoming someone else's problem
Point (2)(h) asks you to keep essential and basic functions running, also after an incident. Point (2)(i) is the only requirement in Annex I Part I that is not about protecting your own user.
ReadWhat the product collects, what it records, and what it can be made to forget
Annex I points (2)(g), (2)(l) and (2)(m) are one data lifecycle, and they pull against each other. The logging duty is unconditional, the opt-out is not, and factory reset is usually not erasure.
ReadIntegrity, attack surface and exploitation mitigation: three points, one argument
Annex I points (2)(f), (2)(j) and (2)(k) read as one engineering sequence: make it hard to change what should not change, leave less to attack, and make a successful attack buy less.
ReadWho gets in, and what they can read
Annex I points (2)(d) and (2)(e) cover access control and confidentiality, including a reporting duty most teams miss and a phrase, state of the art, that no cited standard defines for the CRA yet.
ReadSecure by default, and the requirement that sits above the list
Annex I point (2)(b) is one sentence carrying three separate duties. Point (1) is the only Part I requirement you cannot mark not applicable. Here is what each asks of a connected device, a firmware image and a piece of software.
ReadWhat goes in a CRA technical file: Annex VII part by part, and what satisfies each
The eight parts of the Annex VII technical documentation, with the evidence that satisfies each one and where it comes from inside your business.
ReadThe full CRA Annex III and Annex IV product list, and the four entries people get wrong
Every important and critical product category under the Cyber Resilience Act, quoted from the Official Journal, with the misreadings that change a conformity route.
ReadThe CRA timeline: every date that matters, and the one that already passed
Entry into force, 11 June 2026, 11 September 2026 and 11 December 2027, plus the per-product clocks that run from the day you place a product on the market.
ReadYou need a PSIRT. The CRA just does not call it that
The regulation asks for eight vulnerability-handling duties, a contact address printed in the product documentation, and a clock measured in hours. Nothing part-time survives five years of that.
ReadWrite the evidence once. Four regimes want most of the same file
RED, the CRA, the Machinery Regulation and the US Cyber Trust Mark ask different questions and want largely the same underlying evidence. Here is what actually transfers, and what does not.
ReadWhen does a change make it a new product?
Ship an update and the question follows: is this still the product you assessed? The Commission's July 2026 guidance finally answers it, and the answer is narrower than most teams fear.
ReadHow long must you support it? Five years is not the answer
The five-year figure is a safeguard, not a default. The Commission's guidance is explicit, and getting this wrong is the easiest way to publish a support period that does not comply.
ReadWhen your cloud backend is part of the product
Pure SaaS sits outside the CRA. A backend your product cannot work without does not. The Art. 3(2) test has three parts and all three must hold.
ReadOne assessment for a range of variants
Six variants of the same product do not need six risk assessments. The Commission's guidance sets out when one covers the group, and the deciding factor is narrower than you might expect.
ReadThe Commission's first CRA guidance, decoded: what it actually answers
On 27 July 2026 the European Commission published its first official guidance on applying the CRA. Here is what it covers, and what to do with it.
ReadWhat an SBOM is, and why the CRA asks for one
A software bill of materials is an inventory of what is inside your software. Here is what it is, why the CRA wants it, and how to produce one.
ReadWhat a CRA technical file actually contains
The Annex VII technical file is the evidence behind your Declaration of Conformity. Here is what goes in it, and why it cannot be backfilled.
ReadSelf-assessment vs notified body: why most products skip the lab
The CRA lets the majority of manufacturers assess their own products. Here is who can, who cannot, and what self-assessment actually involves.
ReadThe two CRA dates that matter: 11 September 2026 and 11 December 2027
One date is a reporting duty on a 24-hour clock. The other is your license to keep selling in the EU. Here is what each means.
ReadDoes the CRA apply to your product? A 60-second test
Three questions decide whether the Cyber Resilience Act covers what you sell. Here they are, with the edge cases that trip people up.
ReadWhat the Cyber Resilience Act actually is, in plain English
The CRA in one read: what it covers, who it binds, and the two dates that decide how urgent it is for you.
ReadTerminology
CRA glossary: every term, in plain language
CE marking, conformity assessment, technical file, SBOM, notified body, substantial modification, severe incident, and more, each defined in a sentence or two.
Open the glossary