Cyber Resilience Act resources
Page 13 of 14
Showing resources 181 to 195 of 202.
How Quickly Must CRA Security Updates Be Released?
Understand CRA security-update timing, including risk-based remediation without delay, secure distribution in a timely manner, dissemination of available updates without delay and the distinction from Article 14 reporting deadlines.
READ GUIDE Vulnerability handling and security updates / 11How to Determine the CRA Support Period
Learn how manufacturers determine the Cyber Resilience Act support period using expected product use, reasonable user expectations, intended purpose, relevant Union law, operating-environment availability and third-party component support.
READ GUIDE Conformity assessment / 06CRA Conformity Assessment Module C Explained
Understand CRA Module C conformity to EU-type based on internal production control, including its relationship with Module B, production monitoring, Annex I requirements, CE marking, declaration of conformity and evidence retention.
READ GUIDE Conformity assessment / 07CRA Conformity Assessment Module H Explained
Understand CRA Module H full quality assurance, including the approved quality system, notified-body assessment, design and development controls, vulnerability handling, surveillance, periodic audits, CE marking and evidence retention.
READ GUIDE Conformity assessment / 08What Are CRA Notified Bodies?
Learn what Cyber Resilience Act notified bodies are, how conformity assessment bodies become notified, how to verify their scope, what Article 47 requires and how notified bodies differ from ordinary testing labs and consultancies.
READ GUIDE Cloud, SaaS and remote processing / 12Updating Remote Processing Components
Understand how Cyber Resilience Act update requirements apply to remote processing components, cloud backends, APIs and other manufacturer-controlled remote software throughout the product support period.
READ GUIDE Cloud, SaaS and remote processing / 13Documenting Cloud Dependencies in CRA Technical Files
Learn how manufacturers should document remote processing and cloud dependencies in Cyber Resilience Act technical documentation, including architecture, software versions, risk assessment, SBOM, secure updates and third-party services.
READ GUIDE Cloud, SaaS and remote processing / 14CRA Shared-Responsibility Models for Cloud-Connected Products
Understand how cloud shared-responsibility models interact with Cyber Resilience Act manufacturer obligations, including IaaS, PaaS, SaaS, remote processing, provider controls, configuration responsibility and product risk.
READ GUIDE Vulnerability handling and security updates / 12CRA Requirements at the End of a Product's Support Period
Understand what happens when a CRA product reaches the end of its support period, including vulnerability-handling boundaries, continued availability of issued security updates, unsupported-software warnings, technical-documentation retention and end-of-support communication.
READ GUIDE Vulnerability handling and security updates / 13Handling Vulnerabilities in Unsupported Dependencies
Learn how CRA manufacturers should handle vulnerabilities in unsupported third-party and open-source dependencies, including component due diligence, upstream reporting, remediation, replacement, backporting and support-period planning.
READ GUIDE Vulnerability handling and security updates / 14Backporting Security Fixes to Older Product Versions
Understand when CRA manufacturers may need to backport security fixes, when users can instead be moved to a later substantially modified software version, and how to test and document security fixes for older supported versions.
READ GUIDE Conformity assessment / 09How to Choose a CRA Conformity Assessment Body
Learn how to choose a Cyber Resilience Act conformity assessment body by checking notified-body status, notification scope, CRA module coverage, product competence, language, subcontracting, change procedures and appeals.
READ GUIDE Conformity assessment / 10What Is the CRA EU Declaration of Conformity?
Learn what the Cyber Resilience Act EU declaration of conformity is, when it is drawn up, what Annex V requires, how the simplified Annex VI declaration works and how long the declaration must be retained.
READ GUIDE Conformity assessment / 11CRA CE Marking Requirements
Understand Cyber Resilience Act CE marking requirements, including when the mark can be affixed, placement on products and software, visibility rules, the sub-5 mm exception and the Module H notified-body identification number.
READ GUIDE Product assessment / 03Product categories and classification
Understand the difference between general products, important categories and critical categories without guessing from a product name.
READ GUIDE