Cyber Resilience Act resources
Page 11 of 14
Showing resources 151 to 165 of 202.
Version Control for CRA Compliance Evidence
Learn how to version Cyber Resilience Act compliance evidence so risk assessments, architecture, SBOMs, security designs, test reports and declarations remain traceable to the correct product release.
READ GUIDE Cloud, SaaS and remote processingCloud Services, SaaS and Remote Data Processing Under the CRA
Understand how the Cyber Resilience Act treats cloud services, SaaS and remote data processing solutions, including manufacturer-controlled backends, APIs, databases, standalone cloud services and the CRA-NIS2 boundary.
READ GUIDE Cloud, SaaS and remote processing / 01CRA Remote Data Processing Solutions Explained
Learn what a remote data processing solution means under the Cyber Resilience Act, including the Article 3(2) test, manufacturer responsibility, functional dependency, APIs, databases and cloud services.
READ GUIDE Cloud, SaaS and remote processing / 02When a Cloud Backend Becomes Part of a CRA Product
Learn when a cloud backend becomes part of a product with digital elements under the Cyber Resilience Act, using manufacturer responsibility, functional dependency, API, database and third-party cloud tests.
READ GUIDE Vulnerability handling and security updatesCRA Vulnerability Handling, Security Updates and Support Periods
A complete guide to Cyber Resilience Act vulnerability handling, security updates and support periods, including Article 13, Annex I Part II, vulnerability management, coordinated disclosure, update availability and the relationship with Article 14 reporting.
READ GUIDE Vulnerability handling and security updates / 01CRA Vulnerability Handling Requirements Explained
Understand the Cyber Resilience Act vulnerability handling requirements in Annex I Part II, including vulnerability identification, SBOMs, remediation, testing, coordinated disclosure, reporting contacts and secure security-update distribution.
READ GUIDE Vulnerability handling and security updates / 02Building a Vulnerability Management Process for CRA Products
Build an operational CRA vulnerability management process covering intake, triage, affected-version analysis, remediation, testing, disclosure, security updates, Article 14 assessment and support-period tracking.
READ GUIDE Technical documentation / 15Building a CRA Technical File
Build an organised Cyber Resilience Act technical documentation package using Article 31 and Annex VII, including product identification, architecture, vulnerability handling, risk assessment, support-period evidence, standards, test reports and the EU declaration of conformity.
READ GUIDE Cloud, SaaS and remote processing / 03CRA Requirements for Connected Device Cloud Services
Understand how the Cyber Resilience Act applies to cloud services used by connected devices, including manufacturer-developed remote processing, third-party IaaS, risk assessment, technical documentation and security responsibilities.
READ GUIDE Cloud, SaaS and remote processing / 04When Standalone SaaS Falls Outside or Inside CRA Scope
Understand when standalone SaaS is outside the Cyber Resilience Act, when SaaS-related software can enter CRA scope, and how browser-only services, downloadable clients, remote processing and NIS2 differ.
READ GUIDE Cloud, SaaS and remote processing / 05CRA Considerations for Product APIs
Understand how product APIs should be analysed under the Cyber Resilience Act, including manufacturer-developed APIs as remote data processing, third-party APIs, interface boundaries, backend systems, authentication and risk assessment.
READ GUIDE Vulnerability handling and security updates / 03Coordinated Vulnerability Disclosure Under the CRA
Understand the Cyber Resilience Act coordinated vulnerability disclosure requirement, including CVD policy, researcher communication, remediation coordination, fixed-vulnerability disclosure and the distinction from Article 14 reporting.
READ GUIDE Vulnerability handling and security updates / 04Creating a Product Security Contact Point
Learn how to create and operate a CRA product security contact point for vulnerability reports, including Annex I point 6, Annex II single-point-of-contact requirements, intake continuity, triage and evidence.
READ GUIDE Vulnerability handling and security updates / 05Creating a Vulnerability Disclosure Policy
Learn how to create a CRA coordinated vulnerability disclosure policy covering scope, reporting instructions, acknowledgement, investigation, remediation, researcher communication, disclosure coordination and Article 14 escalation.
READ GUIDE Conformity assessment and CE markingCRA Conformity Assessment and CE Marking
Understand Cyber Resilience Act conformity assessment and CE marking, including Article 32 procedures, Module A self-assessment, Module B plus C, Module H, important and critical product rules, technical documentation, the EU declaration of conformity and CE marking.
READ GUIDE