Cyber Resilience Act resources
Page 12 of 14
Showing resources 166 to 180 of 202.
How CRA Conformity Assessment Works
Follow the Cyber Resilience Act conformity assessment process from product classification and cybersecurity risk assessment through technical documentation, Article 32 procedure selection, verification, EU declaration of conformity and CE marking.
READ GUIDE Conformity assessment / 02When Can Manufacturers Self-Assess Under the CRA?
Learn when Cyber Resilience Act manufacturers can use Module A internal control, when important products require third-party conformity assessment, and how the Article 32 free and open-source software exception works.
READ GUIDE Cloud, SaaS and remote processing / 06CRA Security Responsibilities for Mobile-App Backends
Understand Cyber Resilience Act responsibilities for mobile-app backends, including APIs, databases, authentication, third-party cloud infrastructure, remote data processing, risk assessment and backend security.
READ GUIDE Cloud, SaaS and remote processing / 07CRA Security Responsibilities for IoT Cloud Platforms
Understand CRA security responsibilities for IoT cloud platforms, including remote device management, manufacturer-controlled cloud software, third-party infrastructure, authentication, availability, updates and product risk assessment.
READ GUIDE Cloud, SaaS and remote processing / 08CRA Requirements for Cloud Authentication Services
Understand how the Cyber Resilience Act applies to cloud authentication services, including remote data processing, identity and access controls, authentication portals, third-party identity providers and product classification.
READ GUIDE Vulnerability handling and security updates / 06Receiving Vulnerability Reports From Security Researchers
Learn how manufacturers should receive, preserve, acknowledge, validate and route vulnerability reports from security researchers under a CRA vulnerability-handling process.
READ GUIDE Vulnerability handling and security updates / 07Assessing Vulnerability Severity Under the CRA
Learn how to assess vulnerability severity for CRA product security, including impact, exploitability, exposure, affected versions, compensating controls, CVSS and Article 14 reporting.
READ GUIDE Vulnerability handling and security updates / 08Prioritising Security Fixes Under the CRA
Learn how to prioritise CRA security fixes using product risk, exploitability, exposure, impact, active exploitation, affected supported versions, compensating controls and remediation dependencies.
READ GUIDE Conformity assessment / 03When Is Third-Party CRA Conformity Assessment Required?
Learn when the Cyber Resilience Act requires third-party conformity assessment, including the Article 32 rules for important class I, important class II and critical products, notified-body routes and the free and open-source software exception.
READ GUIDE Conformity assessment / 04CRA Conformity Assessment Module A Explained
Understand CRA Module A internal control, including manufacturer responsibility, Annex VII technical documentation, design and development controls, production, vulnerability handling, CE marking and the EU declaration of conformity.
READ GUIDE Conformity assessment / 05CRA Conformity Assessment Module B Explained
Understand CRA Module B EU-type examination, including notified-body review of technical design, development and vulnerability handling, technical documentation, supporting evidence, critical-part specimens, testing and the EU-type examination certificate.
READ GUIDE Cloud, SaaS and remote processing / 09Managing Third-Party Cloud Providers in CRA Products
Learn how manufacturers should manage third-party cloud providers used by CRA-covered products, including remote data processing boundaries, cybersecurity risk assessment, due diligence, provider assurance and technical documentation.
READ GUIDE Cloud, SaaS and remote processing / 10Cloud Availability and Product Security Under the CRA
Understand how cloud availability relates to Cyber Resilience Act product security, including essential and basic functions, denial-of-service resilience, remote processing, cloud outages, fallback and product risk assessment.
READ GUIDE Cloud, SaaS and remote processing / 11Cloud Vulnerabilities Affecting CRA-Covered Products
Learn how manufacturers should handle cloud vulnerabilities affecting CRA-covered products, including remote data processing vulnerabilities, third-party cloud issues, vulnerability remediation, risk assessment and Article 14 reporting boundaries.
READ GUIDE Vulnerability handling and security updates / 09What the CRA Requires for Security Updates
Understand the Cyber Resilience Act security-update requirements covering vulnerability remediation, security-only releases, secure distribution, automatic updating, free-of-charge updates, advisory messages and long-term update availability.
READ GUIDE