Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 13 of 14

Showing resources 181 to 195 of 202.

Vulnerability handling and security updates / 10

How Quickly Must CRA Security Updates Be Released?

Understand CRA security-update timing, including risk-based remediation without delay, secure distribution in a timely manner, dissemination of available updates without delay and the distinction from Article 14 reporting deadlines.

READ GUIDE
Vulnerability handling and security updates / 11

How to Determine the CRA Support Period

Learn how manufacturers determine the Cyber Resilience Act support period using expected product use, reasonable user expectations, intended purpose, relevant Union law, operating-environment availability and third-party component support.

READ GUIDE
Conformity assessment / 06

CRA Conformity Assessment Module C Explained

Understand CRA Module C conformity to EU-type based on internal production control, including its relationship with Module B, production monitoring, Annex I requirements, CE marking, declaration of conformity and evidence retention.

READ GUIDE
Conformity assessment / 07

CRA Conformity Assessment Module H Explained

Understand CRA Module H full quality assurance, including the approved quality system, notified-body assessment, design and development controls, vulnerability handling, surveillance, periodic audits, CE marking and evidence retention.

READ GUIDE
Conformity assessment / 08

What Are CRA Notified Bodies?

Learn what Cyber Resilience Act notified bodies are, how conformity assessment bodies become notified, how to verify their scope, what Article 47 requires and how notified bodies differ from ordinary testing labs and consultancies.

READ GUIDE
Cloud, SaaS and remote processing / 12

Updating Remote Processing Components

Understand how Cyber Resilience Act update requirements apply to remote processing components, cloud backends, APIs and other manufacturer-controlled remote software throughout the product support period.

READ GUIDE
Cloud, SaaS and remote processing / 13

Documenting Cloud Dependencies in CRA Technical Files

Learn how manufacturers should document remote processing and cloud dependencies in Cyber Resilience Act technical documentation, including architecture, software versions, risk assessment, SBOM, secure updates and third-party services.

READ GUIDE
Cloud, SaaS and remote processing / 14

CRA Shared-Responsibility Models for Cloud-Connected Products

Understand how cloud shared-responsibility models interact with Cyber Resilience Act manufacturer obligations, including IaaS, PaaS, SaaS, remote processing, provider controls, configuration responsibility and product risk.

READ GUIDE
Vulnerability handling and security updates / 12

CRA Requirements at the End of a Product's Support Period

Understand what happens when a CRA product reaches the end of its support period, including vulnerability-handling boundaries, continued availability of issued security updates, unsupported-software warnings, technical-documentation retention and end-of-support communication.

READ GUIDE
Vulnerability handling and security updates / 13

Handling Vulnerabilities in Unsupported Dependencies

Learn how CRA manufacturers should handle vulnerabilities in unsupported third-party and open-source dependencies, including component due diligence, upstream reporting, remediation, replacement, backporting and support-period planning.

READ GUIDE
Vulnerability handling and security updates / 14

Backporting Security Fixes to Older Product Versions

Understand when CRA manufacturers may need to backport security fixes, when users can instead be moved to a later substantially modified software version, and how to test and document security fixes for older supported versions.

READ GUIDE
Conformity assessment / 09

How to Choose a CRA Conformity Assessment Body

Learn how to choose a Cyber Resilience Act conformity assessment body by checking notified-body status, notification scope, CRA module coverage, product competence, language, subcontracting, change procedures and appeals.

READ GUIDE
Conformity assessment / 10

What Is the CRA EU Declaration of Conformity?

Learn what the Cyber Resilience Act EU declaration of conformity is, when it is drawn up, what Annex V requires, how the simplified Annex VI declaration works and how long the declaration must be retained.

READ GUIDE
Conformity assessment / 11

CRA CE Marking Requirements

Understand Cyber Resilience Act CE marking requirements, including when the mark can be affixed, placement on products and software, visibility rules, the sub-5 mm exception and the Module H notified-body identification number.

READ GUIDE
Product assessment / 03

Product categories and classification

Understand the difference between general products, important categories and critical categories without guessing from a product name.

READ GUIDE