Skip to content

Blog

Guides, checklists, and deep dives on the EU Cyber Resilience Act and how to prepare for compliance.

What Is the EU Cyber Resilience Act? A Complete Guide for 2026

The EU Cyber Resilience Act requires cybersecurity compliance for digital products by September 2026. Learn who it applies to, what it requires, and how to prepare.

Read article

CRA Compliance Checklist: What You Need Before September 2026

Complete checklist for EU Cyber Resilience Act compliance. Covers SBOMs, vulnerability handling, ENISA reporting, and CE marking requirements.

Read article

How to Generate an SBOM for CRA Compliance

Step-by-step guide to generating a Software Bill of Materials using CycloneDX or SPDX for EU Cyber Resilience Act compliance.

Read article

CRA vs NIS2: What Is the Difference?

CRA regulates products, NIS2 regulates organizations. Learn how these EU cybersecurity regulations differ and which applies to you.

Read article

Free CRA Readiness Scanner for Open Source Projects

Check your CRA readiness score in under a minute with cra-scanner, a free open source CLI tool. No account required.

Read article

CRA and Open Source: What the Steward Role Means for Foundations and Maintainers

What is an open source steward under the CRA? Learn who qualifies, what obligations apply, and how it differs from full manufacturer requirements.

Read article

How to Classify Your Product Under the CRA: Default, Important, and Critical

How to classify your product under the EU Cyber Resilience Act. Covers default, important (Annex III), and critical (Annex IV) categories with examples.

Read article

ENISA Vulnerability Reporting Under the CRA: Timelines, Templates, and Process

How to report actively exploited vulnerabilities to ENISA under the CRA. Covers the 24h, 72h, and 14-day reporting stages with templates.

Read article

Does the CRA Apply to SaaS? Scope, Exemptions, and Edge Cases

Does the EU Cyber Resilience Act apply to SaaS products? Learn the general rule, exemptions, and edge cases where cloud software is in scope.

Read article

CRA Penalties and Enforcement: What Happens If You Don't Comply

CRA non-compliance penalties reach EUR 15 million or 2.5% of turnover. Learn the penalty tiers, enforcement powers, and how to assess your risk.

Read article

CRA Secure Development Requirements: What Annex I Section 1 Means for Your Team

CRA Annex I Section 1 mandates secure by design, secure defaults, and attack surface minimization. Learn what each requirement means and how to implement it.

Read article

CE Marking for Software Under the CRA: A Step-by-Step Guide

Learn when CE marking is required for software under the CRA, how to complete conformity assessment, and how to draft your EU Declaration of Conformity.

Read article

How to Create a Vulnerability Disclosure Policy for CRA Compliance

How to create a CRA-compliant vulnerability disclosure policy. Covers ISO 29147, SECURITY.md templates, coordinated disclosure, and response timelines.

Read article

CRA Supply Chain Security: Managing Third-Party Components

How to manage third-party and open source component security under the CRA. Covers SBOM for transitive dependencies, vendor assessment, and open source risk.

Read article

CRA Compliance for IoT and Connected Devices

How IoT manufacturers can comply with the CRA. Covers firmware updates, OTA security, device lifecycle, Annex IV critical products, and smart home devices.

Read article

CRA vs GDPR: How Cybersecurity and Data Protection Overlap

How the CRA and GDPR overlap on breach notification, data security, and privacy by design. Learn where they align and where requirements differ.

Read article

Automated Vulnerability Monitoring for CRA Compliance

How to set up automated vulnerability monitoring for CRA compliance. Covers OSV.dev, GitHub Advisories, CISA KEV, continuous scanning, and version-aware matching.

Read article

CRA Conformity Assessment: Self-Assessment vs Third-Party Certification

When can you self-assess for CRA compliance? When is a notified body required? Learn the conformity assessment paths for default, important, and critical products.

Read article

CRA Technical Documentation Requirements: What You Need to Prepare

What technical documentation the CRA requires. Covers product descriptions, design docs, risk assessments, SBOMs, test reports, and the EU Declaration of Conformity.

Read article

How to Calculate Your CRA Compliance Readiness Score

Understand your CRA readiness score. Learn the 5 dimensions, how to improve weak areas, benchmarking your score, and using cra-scanner for assessment.

Read article