Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 11 of 14

Showing resources 151 to 165 of 202.

Technical documentation / 14

Version Control for CRA Compliance Evidence

Learn how to version Cyber Resilience Act compliance evidence so risk assessments, architecture, SBOMs, security designs, test reports and declarations remain traceable to the correct product release.

READ GUIDE
Cloud, SaaS and remote processing

Cloud Services, SaaS and Remote Data Processing Under the CRA

Understand how the Cyber Resilience Act treats cloud services, SaaS and remote data processing solutions, including manufacturer-controlled backends, APIs, databases, standalone cloud services and the CRA-NIS2 boundary.

READ GUIDE
Cloud, SaaS and remote processing / 01

CRA Remote Data Processing Solutions Explained

Learn what a remote data processing solution means under the Cyber Resilience Act, including the Article 3(2) test, manufacturer responsibility, functional dependency, APIs, databases and cloud services.

READ GUIDE
Cloud, SaaS and remote processing / 02

When a Cloud Backend Becomes Part of a CRA Product

Learn when a cloud backend becomes part of a product with digital elements under the Cyber Resilience Act, using manufacturer responsibility, functional dependency, API, database and third-party cloud tests.

READ GUIDE
Vulnerability handling and security updates

CRA Vulnerability Handling, Security Updates and Support Periods

A complete guide to Cyber Resilience Act vulnerability handling, security updates and support periods, including Article 13, Annex I Part II, vulnerability management, coordinated disclosure, update availability and the relationship with Article 14 reporting.

READ GUIDE
Vulnerability handling and security updates / 01

CRA Vulnerability Handling Requirements Explained

Understand the Cyber Resilience Act vulnerability handling requirements in Annex I Part II, including vulnerability identification, SBOMs, remediation, testing, coordinated disclosure, reporting contacts and secure security-update distribution.

READ GUIDE
Vulnerability handling and security updates / 02

Building a Vulnerability Management Process for CRA Products

Build an operational CRA vulnerability management process covering intake, triage, affected-version analysis, remediation, testing, disclosure, security updates, Article 14 assessment and support-period tracking.

READ GUIDE
Technical documentation / 15

Building a CRA Technical File

Build an organised Cyber Resilience Act technical documentation package using Article 31 and Annex VII, including product identification, architecture, vulnerability handling, risk assessment, support-period evidence, standards, test reports and the EU declaration of conformity.

READ GUIDE
Cloud, SaaS and remote processing / 03

CRA Requirements for Connected Device Cloud Services

Understand how the Cyber Resilience Act applies to cloud services used by connected devices, including manufacturer-developed remote processing, third-party IaaS, risk assessment, technical documentation and security responsibilities.

READ GUIDE
Cloud, SaaS and remote processing / 04

When Standalone SaaS Falls Outside or Inside CRA Scope

Understand when standalone SaaS is outside the Cyber Resilience Act, when SaaS-related software can enter CRA scope, and how browser-only services, downloadable clients, remote processing and NIS2 differ.

READ GUIDE
Cloud, SaaS and remote processing / 05

CRA Considerations for Product APIs

Understand how product APIs should be analysed under the Cyber Resilience Act, including manufacturer-developed APIs as remote data processing, third-party APIs, interface boundaries, backend systems, authentication and risk assessment.

READ GUIDE
Vulnerability handling and security updates / 03

Coordinated Vulnerability Disclosure Under the CRA

Understand the Cyber Resilience Act coordinated vulnerability disclosure requirement, including CVD policy, researcher communication, remediation coordination, fixed-vulnerability disclosure and the distinction from Article 14 reporting.

READ GUIDE
Vulnerability handling and security updates / 04

Creating a Product Security Contact Point

Learn how to create and operate a CRA product security contact point for vulnerability reports, including Annex I point 6, Annex II single-point-of-contact requirements, intake continuity, triage and evidence.

READ GUIDE
Vulnerability handling and security updates / 05

Creating a Vulnerability Disclosure Policy

Learn how to create a CRA coordinated vulnerability disclosure policy covering scope, reporting instructions, acknowledgement, investigation, remediation, researcher communication, disclosure coordination and Article 14 escalation.

READ GUIDE
Conformity assessment and CE marking

CRA Conformity Assessment and CE Marking

Understand Cyber Resilience Act conformity assessment and CE marking, including Article 32 procedures, Module A self-assessment, Module B plus C, Module H, important and critical product rules, technical documentation, the EU declaration of conformity and CE marking.

READ GUIDE