Find the question behind the requirement.
Browse independent, source-led guides for product and compliance teams.
What is the Cyber Resilience Act?
A product-focused introduction to the EU framework for the cybersecurity of products with digital elements.
READ GUIDE Product assessment / 02Does the CRA apply to your product?
A structured starting point for software, connected hardware and components. This page is a screening guide, not a legal determination.
READ GUIDE Product assessment / 03Product categories and classification
Understand the difference between general products, important categories and critical categories without guessing from a product name.
READ GUIDE Economic operators / 04Manufacturer obligations across the product lifecycle
A practical map from risk assessment and secure development to documentation, conformity, updates and reporting.
READ GUIDE Economic operators / 05Importer and distributor responsibilities
Role-specific checks and response duties for products moving through the supply chain.
READ GUIDE Product controls / 06Essential cybersecurity requirements
A readable entry point to Annex I product properties and vulnerability-handling requirements.
READ GUIDE Engineering / 07Secure development as an implementation practice
A practical workflow linking product risk, architecture, components, verification and maintenance.
READ GUIDE Post-market / 08Vulnerability handling and coordinated response
A workflow for intake, triage, remediation, updates, disclosure and applicable reporting.
READ GUIDE Post-market / 09CRA reporting obligations
Understand the notification trigger, dates and official reporting route.
READ GUIDE Market pathway / 10Conformity assessment and CE marking
A product-led view of assessment routes, technical documentation, the EU declaration and CE marking.
READ GUIDE Evidence / 11Technical documentation and product evidence
Organise risk, design, verification and support records into a traceable product file.
READ GUIDE Regulatory milestones / 12CRA timeline and application dates
Verified dates for entry into force, reporting and the main CRA obligations.
READ GUIDE Implementation / 13Product security preparation checklist
A working list for teams preparing product evidence and responsibilities.
READ GUIDE Field notes / ArticleHow to scope a software product under the CRA
An editorial guide to product boundaries, components and remote functions.
READ GUIDE