Knowledge Base 25 Articles

CRA Compliance Blog & Guides

Practical, in-depth articles on EU Cyber Resilience Act compliance. Written for engineering teams and product leaders who need actionable guidance.

🗺️
Guide · 12 min read · March 2026

CRA Compliance Step-by-Step: The Complete 2026 Roadmap

A practical 8-step roadmap to achieve EU Cyber Resilience Act compliance. From initial assessment to CE marking — with free tools at every step.

☁️
Industry · 10 min read · March 2026

CRA for SaaS Companies: What You Actually Need to Do

Pure browser-based SaaS is generally exempt from CRA under Recital (12). Learn when CRA does apply to cloud products and which requirements matter for downloadable components and SaaS-adjacent products.

🔧
Tools · 8 min read · March 2026

SBOM Tools Comparison 2026: CycloneDX vs SPDX vs Syft vs Trivy

Hands-on comparison of the top SBOM generation tools for CRA compliance. Which format and tool should you choose for your stack?

⚖️
Comparison · 7 min read · March 2026

CRA vs ISO 27001: Do You Need Both?

ISO 27001 covers organisational security; CRA covers product security. Understand the overlap and gaps between these two frameworks.

⚠️
Legal · 8 min read · March 2026

CRA Penalties Explained: Fines, Market Bans, and Enforcement

Up to €15 million or 2.5% of global turnover. Learn what triggers CRA penalties, who enforces them, and how to protect your business.

📝
Implementation · 9 min read · March 2026

How to Write a CRA-Compliant Vulnerability Disclosure Policy

Step-by-step guide to creating a VDP that satisfies CRA Annex I Part II, §5. Includes templates, security.txt setup, and safe harbour language.

🇺🇸
Industry · 8 min read · March 2026

CRA for US Companies: EU Market Access Requirements

The CRA has extraterritorial reach. If you sell digital products to EU customers, this guide explains your obligations.

🔓
Industry · 10 min read · March 2026

CRA & Open Source: Exemptions, Stewards, and Commercial Use

Non-commercial open source is exempt from CRA — but commercial use is not. Learn about the new "open-source steward" role.

Implementation · 7 min read · March 2026

CE Marking for Software Under CRA: A Practical Guide

CE marking isn't just for physical products. Learn how to apply the CE mark to your digital product and create a valid Declaration of Conformity.

🚨
Implementation · 9 min read · March 2026

CRA Article 14: The 24h/72h/14d Incident Reporting Guide

Actively exploited vulnerabilities must be reported to ENISA within 24 hours starting September 2026.

🔒
Checklist · 6 min read · March 2026

Secure by Default Checklist for CRA Compliance

CRA requires products to ship with the most restrictive secure defaults. Use this checklist to audit your product's default configuration.

📱
Industry · 8 min read · March 2026

CRA for Mobile Apps: iOS & Android Compliance Guide

Mobile apps connecting to online services are subject to CRA. Learn about app store distribution, SDK responsibilities, and update requirements.

📊
Implementation · 11 min read · March 2026

How to Conduct a CRA Product Risk Assessment (Article 13 + Annex I)

A walkthrough of CRA's mandatory product risk assessment using the BSI TR-03183-1 framework.

🔐
Comparison · 7 min read · March 2026

CRA vs GDPR: How Product Security Supports Data Protection

CRA and GDPR are complementary EU regulations. Learn how CRA's security requirements support GDPR Article 32.

📋
Guide · 9 min read · March 2026

CRA Product Classification: Default vs Class I vs Class II

Your CRA classification determines which conformity assessment you need. Use this guide to identify your product's classification tier.

🇪🇺
Guide · 9 min read · March 2026

EU Cyber Resilience Act Summary: Everything You Need to Know

A comprehensive, easy-to-understand summary of the CRA. Who it affects, what the requirements are, and when they come into force.

☑️
Checklist · 5 min read · March 2026

Cyber Resilience Act Compliance Checklist

The ultimate compliance checklist for software developers and hardware manufacturers. Track your progress toward full CRA compliance.

⚙️
Guide · 14 min read · March 2026

Breakdown of the 22 Cyber Resilience Act Requirements

An engineer-friendly breakdown of Annex I: the core security and vulnerability handling requirements of the CRA.

📅
Legal · 6 min read · March 2026

Cyber Resilience Act Timeline and Deadlines

Map out your compliance journey with our detailed CRA implementation timeline spanning 2024 to 2027.

🚀
Industry · 8 min read · March 2026

CRA for Startups: How Early-Stage Companies Can Comply

Regulation can be heavy for startups. Here is how agile teams can achieve CRA compliance without slowing down feature delivery.

🔌
Industry · 11 min read · March 2026

CRA for IoT Manufacturers: Securing Connected Devices

Hardware meets software. How IoT device makers must navigate the Cyber Resilience Act to legally sell in Europe.

🛡️
Comparison · 7 min read · March 2026

Cyber Resilience Act vs NIS2: Understanding the EU Framework

How the CRA (product security) intersects with the NIS2 Directive (entity security) to form the EU cybersecurity shield.

💻
Legal · 6 min read · March 2026

The Exact Definition of 'Products with Digital Elements' under the CRA

Does your software or hardware fall under the CRA? We break down the legal definition of 'products with digital elements'.

📅
Guide · 8 min read · March 2026

How Long Do Security Updates Last Under the CRA?

The CRA mandates security support for at least 5 years, or for the expected use time when shorter. Learn support period factors and examples for different product types.

⚖️
Comparison · 9 min read · March 2026

CRA Self-Assessment vs Notified Body Audit

Module A vs Module B+C. How to know if you can self-certify for the CRA or if you must pay an external auditor.

Ready to Start Your CRA Compliance Journey?

Take our free 6-minute assessment to find out which CRA requirements apply to your product.