Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 19 of 22

Showing resources 271 to 285 of 324.

CRA standards, guidance and rulemaking / 09

CRA and ISO 27001

Understand how ISO/IEC 27001 can support CRA governance, risk management and evidence without automatically establishing product-level conformity or Article 27 presumption of conformity.

READ GUIDE
CRA standards, guidance and rulemaking / 10

CRA and IEC 62443

Learn how the IEC 62443 series can support CRA work for industrial automation and control products, especially secure product development and technical component security, without automatically establishing CRA conformity.

READ GUIDE
CRA standards, guidance and rulemaking / 11

CRA and ETSI EN 303 645

Understand how ETSI EN 303 645 can support CRA readiness for consumer IoT products, where its baseline provisions overlap with Annex I and why the current standard should not be treated as automatic CRA presumption of conformity.

READ GUIDE
CRA standards, guidance and rulemaking / 12

CRA and ISO/IEC 29147 Vulnerability Disclosure

Learn how ISO/IEC 29147:2018 vulnerability-disclosure practices can support CRA coordinated vulnerability disclosure, reporting contacts and fixed-vulnerability communication without replacing CRA-specific legal duties.

READ GUIDE
CRA standards, guidance and rulemaking / 13

CRA and ISO/IEC 30111 Vulnerability Handling

Learn how ISO/IEC 30111:2019 vulnerability-handling processes can support CRA validation, triage, remediation and closure while keeping CRA reporting, support-period and update obligations separate.

READ GUIDE
CRA standards, guidance and rulemaking / 14

How to Map Existing Cybersecurity Standards to CRA Requirements

A practical method for mapping ISO, IEC, ETSI and other cybersecurity standards to CRA Annex I requirements while preserving product-specific gaps, evidence traceability and legal-status distinctions.

READ GUIDE
CRA standards, guidance and rulemaking / 15

How Companies Should Monitor CRA Regulatory Updates

Build a living Cyber Resilience Act regulatory-monitoring process covering EUR-Lex, Official Journal publications, Commission implementation and standardisation updates, ENISA guidance, delegated acts, implementing acts and standards changes.

READ GUIDE
CRA enforcement / 03

What Information Can CRA Authorities Request?

What Cyber Resilience Act market surveillance authorities can request from economic operators, including technical data, internal documentation, embedded software information and supply-chain records.

READ GUIDE
CRA enforcement / 04

CRA Product Investigations Explained

How Cyber Resilience Act product investigations work, including authority triggers, Article 54 significant-risk evaluations, inspections, product sampling, reverse engineering, evidence review and cross-border escalation.

READ GUIDE
CRA enforcement / 05

Corrective Actions for Non-Compliant Digital Products

What corrective action means under the Cyber Resilience Act when a product with digital elements is found non-compliant, including remediation, market restrictions, withdrawal, recall and procedural rights.

READ GUIDE
CRA enforcement / 06

Product Withdrawal Under the CRA

Understand product withdrawal under the Cyber Resilience Act, including what withdrawal means, when market surveillance authorities can require it, how it differs from recall and what evidence manufacturers should preserve.

READ GUIDE
CRA enforcement / 07

Product Recall Under the CRA

Understand product recall under the Cyber Resilience Act, including when authorities can require the return of products already supplied to end users, how recall differs from withdrawal and how manufacturers should manage recall evidence.

READ GUIDE
CRA enforcement / 08

What Is Formal Non-Compliance Under the CRA?

Understand formal non-compliance under CRA Article 58, including CE marking problems, EU declaration of conformity defects, notified-body identification issues and unavailable or incomplete technical documentation.

READ GUIDE
CRA and overlapping EU regulation / Pillar

How the Cyber Resilience Act Fits Into the Wider EU Product and Digital Regulatory Framework

A practical guide to how the Cyber Resilience Act fits alongside EU product safety, product liability, machinery, data, privacy, medical-device, automotive and other sector-specific legislation without assuming that one law automatically replaces another.

READ GUIDE
CRA and overlapping EU regulation / 01

Cyber Resilience Act and the Product Liability Directive

How the Cyber Resilience Act interacts with Directive (EU) 2024/2853 on liability for defective products, including software, cybersecurity defects, security updates, manufacturer control, defectiveness and compensation claims.

READ GUIDE