Blog
Guides, checklists, and deep dives on the EU Cyber Resilience Act and how to prepare for compliance.
What Is the EU Cyber Resilience Act? A Complete Guide for 2026
The EU Cyber Resilience Act requires cybersecurity compliance for digital products by September 2026. Learn who it applies to, what it requires, and how to prepare.
Read articleCRA Compliance Checklist: What You Need Before September 2026
Complete checklist for EU Cyber Resilience Act compliance. Covers SBOMs, vulnerability handling, ENISA reporting, and CE marking requirements.
Read articleHow to Generate an SBOM for CRA Compliance
Step-by-step guide to generating a Software Bill of Materials using CycloneDX or SPDX for EU Cyber Resilience Act compliance.
Read articleCRA vs NIS2: What Is the Difference?
CRA regulates products, NIS2 regulates organizations. Learn how these EU cybersecurity regulations differ and which applies to you.
Read articleFree CRA Readiness Scanner for Open Source Projects
Check your CRA readiness score in under a minute with cra-scanner, a free open source CLI tool. No account required.
Read articleCRA and Open Source: What the Steward Role Means for Foundations and Maintainers
What is an open source steward under the CRA? Learn who qualifies, what obligations apply, and how it differs from full manufacturer requirements.
Read articleHow to Classify Your Product Under the CRA: Default, Important, and Critical
How to classify your product under the EU Cyber Resilience Act. Covers default, important (Annex III), and critical (Annex IV) categories with examples.
Read articleENISA Vulnerability Reporting Under the CRA: Timelines, Templates, and Process
How to report actively exploited vulnerabilities to ENISA under the CRA. Covers the 24h, 72h, and 14-day reporting stages with templates.
Read articleDoes the CRA Apply to SaaS? Scope, Exemptions, and Edge Cases
Does the EU Cyber Resilience Act apply to SaaS products? Learn the general rule, exemptions, and edge cases where cloud software is in scope.
Read articleCRA Penalties and Enforcement: What Happens If You Don't Comply
CRA non-compliance penalties reach EUR 15 million or 2.5% of turnover. Learn the penalty tiers, enforcement powers, and how to assess your risk.
Read articleCRA Secure Development Requirements: What Annex I Section 1 Means for Your Team
CRA Annex I Section 1 mandates secure by design, secure defaults, and attack surface minimization. Learn what each requirement means and how to implement it.
Read articleCE Marking for Software Under the CRA: A Step-by-Step Guide
Learn when CE marking is required for software under the CRA, how to complete conformity assessment, and how to draft your EU Declaration of Conformity.
Read articleHow to Create a Vulnerability Disclosure Policy for CRA Compliance
How to create a CRA-compliant vulnerability disclosure policy. Covers ISO 29147, SECURITY.md templates, coordinated disclosure, and response timelines.
Read articleCRA Supply Chain Security: Managing Third-Party Components
How to manage third-party and open source component security under the CRA. Covers SBOM for transitive dependencies, vendor assessment, and open source risk.
Read articleCRA Compliance for IoT and Connected Devices
How IoT manufacturers can comply with the CRA. Covers firmware updates, OTA security, device lifecycle, Annex IV critical products, and smart home devices.
Read articleCRA vs GDPR: How Cybersecurity and Data Protection Overlap
How the CRA and GDPR overlap on breach notification, data security, and privacy by design. Learn where they align and where requirements differ.
Read articleAutomated Vulnerability Monitoring for CRA Compliance
How to set up automated vulnerability monitoring for CRA compliance. Covers OSV.dev, GitHub Advisories, CISA KEV, continuous scanning, and version-aware matching.
Read articleCRA Conformity Assessment: Self-Assessment vs Third-Party Certification
When can you self-assess for CRA compliance? When is a notified body required? Learn the conformity assessment paths for default, important, and critical products.
Read articleCRA Technical Documentation Requirements: What You Need to Prepare
What technical documentation the CRA requires. Covers product descriptions, design docs, risk assessments, SBOMs, test reports, and the EU Declaration of Conformity.
Read articleHow to Calculate Your CRA Compliance Readiness Score
Understand your CRA readiness score. Learn the 5 dimensions, how to improve weak areas, benchmarking your score, and using cra-scanner for assessment.
Read article