Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 15 of 22

Showing resources 211 to 225 of 324.

CRA readiness, templates, tools and software / 09

CRA Technical Documentation Checklist

A practical Cyber Resilience Act technical documentation checklist based on Article 31 and Annex VII, covering product description, architecture, cybersecurity risk assessment, vulnerability handling, SBOM, standards, testing and the EU declaration of conformity.

READ GUIDE
CRA readiness, templates, tools and software / 10

CRA Conformity Assessment Checklist

A practical Cyber Resilience Act conformity assessment checklist covering product classification, Article 32 route selection, technical documentation, notified-body involvement, standards, EU declaration of conformity and CE marking.

READ GUIDE
CRA readiness, templates, tools and software / 11

CRA Supplier Security Questionnaire

A practical Cyber Resilience Act supplier security questionnaire for gathering third-party component, vulnerability, update, support, SBOM, secure development and security-contact information needed for manufacturer due diligence.

READ GUIDE
CRA readiness, templates, tools and software / 12

CRA Support Period Tracker

A practical Cyber Resilience Act support period tracker for recording expected product use, Article 13 factors, support-period reasoning, supported versions, vulnerability-handling coverage and end-of-support milestones.

READ GUIDE
CRA readiness, templates, tools and software / 13

CRA Compliance Software Features

A practical guide to Cyber Resilience Act compliance software features for product inventory, classification, cybersecurity risk assessment, requirements mapping, SBOM, vulnerability handling, reporting, technical documentation, conformity assessment and support-period tracking.

READ GUIDE
CRA readiness, templates, tools and software / 14

Build vs Buy CRA Compliance Software

A practical build-versus-buy guide for Cyber Resilience Act compliance software, comparing product modelling, integrations, workflow, evidence traceability, reporting, technical documentation, data control, vendor risk and total cost.

READ GUIDE
CRA readiness, templates, tools and software / 15

CRA Compliance Dashboard

A practical guide to designing a Cyber Resilience Act compliance dashboard that shows product scope, classification, risk, evidence quality, vulnerabilities, Article 14 reporting readiness, technical documentation, conformity status and support-period milestones without reducing conformity to a single score.

READ GUIDE
CRA software supply chain / Pillar

CRA Software Supply Chain Security and SBOM Requirements

A practical guide to Cyber Resilience Act software supply chain security, third-party components, dependency due diligence, SBOM requirements, vulnerability handling and lifecycle evidence.

READ GUIDE
CRA software supply chain / 01

What the CRA Means for Software Supply Chain Security

How the Cyber Resilience Act applies to third-party software components, open-source dependencies, supplier due diligence, component vulnerabilities and lifecycle security.

READ GUIDE
CRA software supply chain / 02

What the CRA Says About Software Bills of Materials

A focused explanation of Cyber Resilience Act SBOM requirements, including the CRA definition, machine-readable format, top-level dependencies, technical documentation, user disclosure and authority access.

READ GUIDE
CRA software supply chain / 03

Building an SBOM for CRA Readiness

How to build and maintain a CRA-ready software bill of materials, including scope, machine-readable formats, release versioning, dependency depth and evidence ownership.

READ GUIDE
CRA software supply chain / 04

Identifying Third-Party Components in Digital Products

How manufacturers can identify and document third-party software, firmware and hardware components for CRA supply chain security, SBOMs and vulnerability handling.

READ GUIDE
CRA software supply chain / 05

Managing Open Source Dependencies Under the CRA

How manufacturers should select, document, monitor and remediate open-source dependencies under the Cyber Resilience Act without confusing manufacturer duties with the separate open-source steward regime.

READ GUIDE
CRA software supply chain / 06

Tracking Vulnerabilities Across Software Dependencies

How CRA manufacturers can map vulnerability intelligence to direct and transitive software dependencies, affected product versions and remediation decisions.

READ GUIDE
CRA software supply chain / 07

Handling Vulnerable Third-Party Libraries

A CRA-focused process for responding when a third-party library has a known vulnerability, from impact analysis and upstream coordination to remediation, testing and release.

READ GUIDE