CRA Compliance Blog & Guides
Practical, in-depth articles on EU Cyber Resilience Act compliance. Written for engineering teams and product leaders who need actionable guidance.
CRA Compliance Step-by-Step: The Complete 2026 Roadmap
A practical 8-step roadmap to achieve EU Cyber Resilience Act compliance. From initial assessment to CE marking — with free tools at every step.
CRA for SaaS Companies: What You Actually Need to Do
Pure browser-based SaaS is generally exempt from CRA under Recital (12). Learn when CRA does apply to cloud products and which requirements matter for downloadable components and SaaS-adjacent products.
SBOM Tools Comparison 2026: CycloneDX vs SPDX vs Syft vs Trivy
Hands-on comparison of the top SBOM generation tools for CRA compliance. Which format and tool should you choose for your stack?
CRA vs ISO 27001: Do You Need Both?
ISO 27001 covers organisational security; CRA covers product security. Understand the overlap and gaps between these two frameworks.
CRA Penalties Explained: Fines, Market Bans, and Enforcement
Up to €15 million or 2.5% of global turnover. Learn what triggers CRA penalties, who enforces them, and how to protect your business.
How to Write a CRA-Compliant Vulnerability Disclosure Policy
Step-by-step guide to creating a VDP that satisfies CRA Annex I Part II, §5. Includes templates, security.txt setup, and safe harbour language.
CRA for US Companies: EU Market Access Requirements
The CRA has extraterritorial reach. If you sell digital products to EU customers, this guide explains your obligations.
CRA & Open Source: Exemptions, Stewards, and Commercial Use
Non-commercial open source is exempt from CRA — but commercial use is not. Learn about the new "open-source steward" role.
CE Marking for Software Under CRA: A Practical Guide
CE marking isn't just for physical products. Learn how to apply the CE mark to your digital product and create a valid Declaration of Conformity.
CRA Article 14: The 24h/72h/14d Incident Reporting Guide
Actively exploited vulnerabilities must be reported to ENISA within 24 hours starting September 2026.
Secure by Default Checklist for CRA Compliance
CRA requires products to ship with the most restrictive secure defaults. Use this checklist to audit your product's default configuration.
CRA for Mobile Apps: iOS & Android Compliance Guide
Mobile apps connecting to online services are subject to CRA. Learn about app store distribution, SDK responsibilities, and update requirements.
How to Conduct a CRA Product Risk Assessment (Article 13 + Annex I)
A walkthrough of CRA's mandatory product risk assessment using the BSI TR-03183-1 framework.
CRA vs GDPR: How Product Security Supports Data Protection
CRA and GDPR are complementary EU regulations. Learn how CRA's security requirements support GDPR Article 32.
CRA Product Classification: Default vs Class I vs Class II
Your CRA classification determines which conformity assessment you need. Use this guide to identify your product's classification tier.
EU Cyber Resilience Act Summary: Everything You Need to Know
A comprehensive, easy-to-understand summary of the CRA. Who it affects, what the requirements are, and when they come into force.
Cyber Resilience Act Compliance Checklist
The ultimate compliance checklist for software developers and hardware manufacturers. Track your progress toward full CRA compliance.
Breakdown of the 22 Cyber Resilience Act Requirements
An engineer-friendly breakdown of Annex I: the core security and vulnerability handling requirements of the CRA.
Cyber Resilience Act Timeline and Deadlines
Map out your compliance journey with our detailed CRA implementation timeline spanning 2024 to 2027.
CRA for Startups: How Early-Stage Companies Can Comply
Regulation can be heavy for startups. Here is how agile teams can achieve CRA compliance without slowing down feature delivery.
CRA for IoT Manufacturers: Securing Connected Devices
Hardware meets software. How IoT device makers must navigate the Cyber Resilience Act to legally sell in Europe.
Cyber Resilience Act vs NIS2: Understanding the EU Framework
How the CRA (product security) intersects with the NIS2 Directive (entity security) to form the EU cybersecurity shield.
The Exact Definition of 'Products with Digital Elements' under the CRA
Does your software or hardware fall under the CRA? We break down the legal definition of 'products with digital elements'.
How Long Do Security Updates Last Under the CRA?
The CRA mandates security support for at least 5 years, or for the expected use time when shorter. Learn support period factors and examples for different product types.
CRA Self-Assessment vs Notified Body Audit
Module A vs Module B+C. How to know if you can self-certify for the CRA or if you must pay an external auditor.
Ready to Start Your CRA Compliance Journey?
Take our free 6-minute assessment to find out which CRA requirements apply to your product.