Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 17 of 22

Showing resources 241 to 255 of 324.

CRA importers and distributors / 04

Checking CE Marking Before Importing CRA-Covered Products

How EU importers should verify CE marking as part of the CRA Article 19 market-access process and what CE marking does and does not establish.

READ GUIDE
CRA importers and distributors / 05

Checking the EU Declaration of Conformity

What CRA importers and market-access teams should verify when reviewing the EU declaration of conformity for products with digital elements.

READ GUIDE
CRA importers and distributors / 06

Importer Identification Requirements Under the CRA

What Article 19 requires EU importers to place on CRA-covered products or accompanying materials, including name, postal address and digital contact information.

READ GUIDE
CRA importers and distributors / 07

What Importers Should Do When a Product Is Non-Compliant

How CRA importers should respond to suspected or confirmed non-conformity before and after market placement, including holds, corrective measures, withdrawal, recall and authority notification.

READ GUIDE
CRA importers and distributors / 08

What Distributors Should Do When a Product Is Non-Compliant

How CRA distributors should respond to suspected or confirmed non-conformity, including stop-supply decisions, corrective measures, withdrawal, recall and authority notification.

READ GUIDE
CRA importers and distributors / 09

CRA Product Traceability Requirements

How Article 23 requires CRA economic operators to identify upstream and downstream economic operators and retain supply-chain information for 10 years.

READ GUIDE
CRA importers and distributors / 10

When an Importer Becomes the Manufacturer

When Article 21 makes a CRA importer the manufacturer because it uses its own name or trademark or substantially modifies a product already placed on the market.

READ GUIDE
CRA importers and distributors / 11

When a Distributor Becomes the Manufacturer

When Article 21 makes a CRA distributor the manufacturer because it uses its own name or trademark or substantially modifies a product already placed on the market.

READ GUIDE
CRA importers and distributors / 12

CRA Requirements Following Product Modification

How product modification can change CRA responsibilities for importers, distributors and other persons, including substantial modification, manufacturer status and conformity reassessment.

READ GUIDE
CRA importers and distributors / 13

Creating a CRA Market-Access Checklist for Non-EU Vendors

A practical pre-market checklist for non-EU manufacturers and EU importers covering CRA roles, conformity evidence, CE marking, declarations, identification, support, traceability and escalation.

READ GUIDE
User information and security communications / 06

Communicating End-of-Support Dates

Learn how CRA manufacturers should communicate end-of-support dates clearly, consistently and in advance, including purchase-time visibility, product identification, migration guidance, unsupported-software warnings and historical update availability.

READ GUIDE
User information and security communications / 07

Providing Vulnerability Reporting Contact Information

Learn how CRA manufacturers should provide vulnerability reporting contact information, including the single point of contact, CVD policy location, two-way communication, discoverability, durability and separation from regulatory reporting channels.

READ GUIDE
User information and security communications / 08

Customer Security Advisories Under the CRA

Learn what CRA customer security advisories should contain, including fixed-vulnerability descriptions, affected products and versions, impact, severity, remediation information, user action and justified disclosure delay.

READ GUIDE
User information and security communications / 09

Communicating Known Security Risks

Learn how CRA manufacturers should communicate known or foreseeable circumstances that may lead to significant cybersecurity risks, including intended use, foreseeable misuse, deployment assumptions, insecure configurations and actionable user precautions.

READ GUIDE
User information and security communications / 10

Security Documentation for Enterprise Customers

Learn how CRA manufacturers can organise Annex II security information for enterprise customers, including product identification, security environment, known risks, support dates, vulnerability contacts, update instructions and integration information without inventing a separate enterprise-only CRA document requirement.

READ GUIDE