Cyber Resilience Act resources
Page 16 of 22
Showing resources 226 to 240 of 324.
Managing End-of-Life Software Dependencies
How CRA manufacturers can identify, assess and replace unsupported software dependencies before they undermine product support-period and vulnerability-handling obligations.
READ GUIDE CRA software supply chain / 09CRA Security Requirements for Commercial Components
How Cyber Resilience Act manufacturer due diligence applies to commercial software, firmware and hardware components, including supplier evidence, updates, vulnerabilities and lifecycle support.
READ GUIDE CRA software supply chain / 10Supplier Security Assessments for CRA Products
A practical framework for assessing software and component suppliers under the Cyber Resilience Act, including evidence, support, vulnerability handling, provenance and change control.
READ GUIDE CRA software supply chain / 11CRA Security Clauses for Software Suppliers
Contract topics manufacturers can use with software and component suppliers to support CRA vulnerability handling, SBOM evidence, support, updates, change control and regulatory cooperation.
READ GUIDE CRA software supply chain / 12Managing Component Updates Throughout the Product Lifecycle
How CRA manufacturers can govern third-party component updates from initial integration through supported releases, security remediation and end-of-support transitions.
READ GUIDE CRA software supply chain / 13Assessing Security Risks in OEM Components
How manufacturers can assess cybersecurity risk in OEM-supplied software, firmware and hardware components under the Cyber Resilience Act.
READ GUIDE CRA software supply chain / 14Software Provenance and CRA Compliance
How software provenance supports CRA component due diligence, SBOM accuracy, dependency trust, build integrity and vulnerability response.
READ GUIDE CRA software supply chain / 15Building a CRA Component and Dependency Inventory
A practical framework for building and maintaining the component and dependency inventory needed for CRA software supply chain security, SBOM generation, vulnerability handling and lifecycle evidence.
READ GUIDE User information and security communications / 03How to Communicate Secure Product Configuration
Learn how CRA manufacturers should communicate secure product configuration, security assumptions, default settings, deployment conditions, security-sensitive changes and user actions without confusing configuration guidance with internal technical controls.
READ GUIDE User information and security communications / 04Communicating Product Support Periods
Learn how CRA manufacturers should communicate product support periods, including the type of technical security support, the support end date, purchase-time visibility, month-and-year precision and the distinction between security support, warranty and update availability.
READ GUIDE User information and security communications / 05Communicating Security Update Availability
Learn how CRA manufacturers should communicate security update availability, affected products, installation paths, advisory messages, user action, support-period expectations and long-term access to already-issued updates.
READ GUIDE CRA importers and distributors / PillarCRA Requirements for Importers and Distributors
A practical guide to Cyber Resilience Act requirements for importers and distributors, including pre-market verification, CE marking, declarations, non-conformity, traceability and manufacturer-role changes.
READ GUIDE CRA importers and distributors / 01What Must CRA Importers Verify Before Selling a Product?
The checks EU importers must complete under Article 19 before placing a CRA-covered product on the Union market.
READ GUIDE CRA importers and distributors / 02What Must CRA Distributors Verify?
The due-care and verification checks distributors must perform under Article 20 before making CRA-covered products available on the Union market.
READ GUIDE CRA importers and distributors / 03CRA Requirements for Products Manufactured Outside the EU
How the Cyber Resilience Act applies when products with digital elements are manufactured outside the EU and enter the Union market through an EU importer.
READ GUIDE