Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 12 of 14

Showing resources 166 to 180 of 202.

Conformity assessment / 01

How CRA Conformity Assessment Works

Follow the Cyber Resilience Act conformity assessment process from product classification and cybersecurity risk assessment through technical documentation, Article 32 procedure selection, verification, EU declaration of conformity and CE marking.

READ GUIDE
Conformity assessment / 02

When Can Manufacturers Self-Assess Under the CRA?

Learn when Cyber Resilience Act manufacturers can use Module A internal control, when important products require third-party conformity assessment, and how the Article 32 free and open-source software exception works.

READ GUIDE
Cloud, SaaS and remote processing / 06

CRA Security Responsibilities for Mobile-App Backends

Understand Cyber Resilience Act responsibilities for mobile-app backends, including APIs, databases, authentication, third-party cloud infrastructure, remote data processing, risk assessment and backend security.

READ GUIDE
Cloud, SaaS and remote processing / 07

CRA Security Responsibilities for IoT Cloud Platforms

Understand CRA security responsibilities for IoT cloud platforms, including remote device management, manufacturer-controlled cloud software, third-party infrastructure, authentication, availability, updates and product risk assessment.

READ GUIDE
Cloud, SaaS and remote processing / 08

CRA Requirements for Cloud Authentication Services

Understand how the Cyber Resilience Act applies to cloud authentication services, including remote data processing, identity and access controls, authentication portals, third-party identity providers and product classification.

READ GUIDE
Vulnerability handling and security updates / 06

Receiving Vulnerability Reports From Security Researchers

Learn how manufacturers should receive, preserve, acknowledge, validate and route vulnerability reports from security researchers under a CRA vulnerability-handling process.

READ GUIDE
Vulnerability handling and security updates / 07

Assessing Vulnerability Severity Under the CRA

Learn how to assess vulnerability severity for CRA product security, including impact, exploitability, exposure, affected versions, compensating controls, CVSS and Article 14 reporting.

READ GUIDE
Vulnerability handling and security updates / 08

Prioritising Security Fixes Under the CRA

Learn how to prioritise CRA security fixes using product risk, exploitability, exposure, impact, active exploitation, affected supported versions, compensating controls and remediation dependencies.

READ GUIDE
Conformity assessment / 03

When Is Third-Party CRA Conformity Assessment Required?

Learn when the Cyber Resilience Act requires third-party conformity assessment, including the Article 32 rules for important class I, important class II and critical products, notified-body routes and the free and open-source software exception.

READ GUIDE
Conformity assessment / 04

CRA Conformity Assessment Module A Explained

Understand CRA Module A internal control, including manufacturer responsibility, Annex VII technical documentation, design and development controls, production, vulnerability handling, CE marking and the EU declaration of conformity.

READ GUIDE
Conformity assessment / 05

CRA Conformity Assessment Module B Explained

Understand CRA Module B EU-type examination, including notified-body review of technical design, development and vulnerability handling, technical documentation, supporting evidence, critical-part specimens, testing and the EU-type examination certificate.

READ GUIDE
Cloud, SaaS and remote processing / 09

Managing Third-Party Cloud Providers in CRA Products

Learn how manufacturers should manage third-party cloud providers used by CRA-covered products, including remote data processing boundaries, cybersecurity risk assessment, due diligence, provider assurance and technical documentation.

READ GUIDE
Cloud, SaaS and remote processing / 10

Cloud Availability and Product Security Under the CRA

Understand how cloud availability relates to Cyber Resilience Act product security, including essential and basic functions, denial-of-service resilience, remote processing, cloud outages, fallback and product risk assessment.

READ GUIDE
Cloud, SaaS and remote processing / 11

Cloud Vulnerabilities Affecting CRA-Covered Products

Learn how manufacturers should handle cloud vulnerabilities affecting CRA-covered products, including remote data processing vulnerabilities, third-party cloud issues, vulnerability remediation, risk assessment and Article 14 reporting boundaries.

READ GUIDE
Vulnerability handling and security updates / 09

What the CRA Requires for Security Updates

Understand the Cyber Resilience Act security-update requirements covering vulnerability remediation, security-only releases, secure distribution, automatic updating, free-of-charge updates, advisory messages and long-term update availability.

READ GUIDE