Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 20 of 22

Showing resources 286 to 300 of 324.

CRA and overlapping EU regulation / 02

Cyber Resilience Act and the General Product Safety Regulation

How the Cyber Resilience Act interacts with Regulation (EU) 2023/988 on general product safety, including consumer products, cybersecurity-related safety risks, software updates, interconnection and the GPSR safety-net function.

READ GUIDE
CRA and overlapping EU regulation / 03

Cyber Resilience Act and the EU Machinery Regulation

How the Cyber Resilience Act interacts with Regulation (EU) 2023/1230 on machinery, including protection against corruption, malicious external influence, safety-related software, control systems, risk assessment, conformity assessment and shared cybersecurity evidence.

READ GUIDE
CRA and overlapping EU regulation / 04

Cyber Resilience Act and the EU Data Act

How the Cyber Resilience Act interacts with Regulation (EU) 2023/2854, the Data Act, including connected-product design, user access to product data, related services, secure data access, security restrictions, personal data and shared technical evidence.

READ GUIDE
CRA and overlapping EU regulation / 05

Cyber Resilience Act and GDPR

How the Cyber Resilience Act interacts with the GDPR, including data protection by design, security of processing, personal-data breaches, CRA Article 14 reporting, product cybersecurity evidence and separate regulatory responsibilities.

READ GUIDE
CRA enforcement / 09

What Happens When a CRA Product Presents a Serious Cybersecurity Risk?

What happens when a CRA product presents a significant cybersecurity risk, including Article 54 evaluation, Article 57 action against compliant but risky products, corrective measures, withdrawal, recall and Union-level coordination.

READ GUIDE
CRA enforcement / 10

CRA Fines and Penalties Explained

Cyber Resilience Act fines and penalties explained, including the EUR 15 million or 2.5 percent tier, EUR 10 million or 2 percent tier, EUR 5 million or 1 percent information tier and the role of national penalty rules.

READ GUIDE
CRA enforcement / 11

CRA Enforcement for Non-EU Manufacturers

How CRA enforcement works for manufacturers established outside the EU, including importer obligations, authorised representatives, the EU-established economic operator requirement, market-surveillance cooperation and corrective measures.

READ GUIDE
CRA enforcement / 12

How Manufacturers Should Prepare for a CRA Authority Request

A practical guide to preparing for Cyber Resilience Act authority requests, including Article 53 data access, technical documentation, product-version evidence, internal records, supply-chain information and response governance.

READ GUIDE
CRA enforcement / 13

Maintaining Evidence for CRA Market-Surveillance Reviews

How to maintain Cyber Resilience Act evidence for market-surveillance reviews, including versioned technical documentation, risk assessments, vulnerability records, conformity evidence, traceability, retention and authority-response history.

READ GUIDE
CRA and overlapping EU regulation / 06

Cyber Resilience Act and Medical Device Cybersecurity

How the Cyber Resilience Act interacts with Regulation (EU) 2017/745 on medical devices, including the CRA Article 2 exclusion, software and connected medical devices, information security, lifecycle risk management, security patches and conformity assessment.

READ GUIDE
CRA and overlapping EU regulation / 07

Cyber Resilience Act and In Vitro Diagnostic Medical Devices

How the Cyber Resilience Act interacts with Regulation (EU) 2017/746 on in vitro diagnostic medical devices, including the CRA Article 2 exclusion, IVD software, information security, IT-network requirements, validation, risk management and lifecycle cybersecurity.

READ GUIDE
CRA and overlapping EU regulation / 08

Cyber Resilience Act and Automotive Cybersecurity

How the Cyber Resilience Act interacts with Regulation (EU) 2019/2144 on vehicle general safety and mandatory vehicle cybersecurity requirements, including the CRA Article 2 exclusion, UN Regulation No 155, cybersecurity management systems, software updates, type approval and product boundaries.

READ GUIDE
CRA by product / Pillar

Cyber Resilience Act Requirements by Product Type

A product-specific guide to applying the Cyber Resilience Act across IoT devices, smart-home products, routers, software, embedded systems, industrial products, developer tools, connected toys, wearables and other digital products.

READ GUIDE
CRA by product / 01

Cyber Resilience Act for IoT Devices

Product-specific Cyber Resilience Act guidance for IoT devices, covering device identity, wireless interfaces, firmware, companion apps, cloud dependencies, secure updates, component risk and conformity classification.

READ GUIDE
CRA by product / 02

Cyber Resilience Act for Smart-Home Products

Product-specific Cyber Resilience Act guidance for smart-home products, including Class I security products, smart locks, cameras, baby monitors, alarm systems, remote control, household roles and conformity assessment.

READ GUIDE