Cyber Resilience Act resources
Page 3 of 8
Showing resources 31 to 45 of 111.
Does Internally Developed Software Fall Under the CRA?
Understand when internally developed or in-house software falls within Cyber Resilience Act scope, including internal use, external supply, group companies, manufacturer status and later commercial distribution.
READ GUIDE CRA scope / 16When Is Software Considered Placed on the EU Market?
Understand when software is placed on the Union market under the Cyber Resilience Act, including first making available, digital distribution, free downloads, commercial activity, software versions and testing releases.
READ GUIDE CRA scope / 17Does Free Software Fall Within CRA Scope?
Understand when free software falls within the Cyber Resilience Act, including free-of-charge commercial software, free and open-source software, monetisation, commercial activity and open-source software stewards.
READ GUIDE CRA reporting / PillarCyber Resilience Act Vulnerability and Incident Reporting Requirements
A practical guide to the Cyber Resilience Act reporting rules for actively exploited vulnerabilities and severe product-security incidents, including the 24-hour, 72-hour and final-report stages.
READ GUIDE CRA reporting / 01What Must Manufacturers Report Under Article 14 of the CRA?
Understand the two mandatory Article 14 reporting triggers for manufacturers, the information required at the 24-hour, 72-hour and final-report stages, and the related user-notification duty.
READ GUIDE CRA reporting / 02What Is an Actively Exploited Vulnerability Under the CRA?
Understand the Cyber Resilience Act definition of an actively exploited vulnerability, the role of reliable evidence and malicious exploitation, and how it differs from a vulnerability that is merely exploitable.
READ GUIDE Essential cybersecurity requirements / PillarCRA Annex I Essential Cybersecurity Requirements Explained
A practical guide to the Cyber Resilience Act Annex I essential cybersecurity requirements, including product-security properties, vulnerability handling, risk assessment, implementation evidence and lifecycle obligations.
READ GUIDE Essential cybersecurity requirements / 01CRA Requirements for Risk-Appropriate Product Security
Understand the CRA requirement to design, develop and produce products with digital elements with an appropriate level of cybersecurity based on the risks, and how to translate that rule into product controls and evidence.
READ GUIDE Essential cybersecurity requirements / 02CRA Rules on Known Exploitable Vulnerabilities
Understand the CRA Annex I rule that products with digital elements should be made available on the market without known exploitable vulnerabilities, including its relationship to risk assessment, components, release gates and vulnerability handling.
READ GUIDE CRA product classification / PillarImportant and Critical Products Under the Cyber Resilience Act
Understand how the Cyber Resilience Act classifies important and critical products with digital elements, how the core-functionality test works, and why classification changes the available conformity assessment route.
READ GUIDE CRA product classification / 01What Is an Important Product With Digital Elements?
Learn what an important product with digital elements means under Article 7 of the Cyber Resilience Act, how the core-functionality test works, and how Annex III classification affects conformity assessment.
READ GUIDE CRA product classification / 02CRA Important Products Class I Explained
Understand CRA Important Products Class I, the Annex III categories, the core-functionality test, and when a Class I product can use internal control or needs a stricter conformity assessment procedure.
READ GUIDE CRA reporting / 03What Is a Severe Incident Under the Cyber Resilience Act?
Understand when an incident is considered severe under Article 14 of the Cyber Resilience Act, including impacts on security properties, sensitive functions and malicious code.
READ GUIDE CRA reporting / 04Understanding the CRA 24-Hour Early Warning
Understand the Cyber Resilience Act 24-hour early-warning requirement for actively exploited vulnerabilities and severe incidents, including timing, minimum information and manufacturer awareness.
READ GUIDE CRA reporting / 05Understanding the CRA 72-Hour Notification
Understand what manufacturers must provide in the Cyber Resilience Act 72-hour notification for actively exploited vulnerabilities and severe incidents and how it differs from the 24-hour warning.
READ GUIDE