Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 3 of 8

Showing resources 31 to 45 of 111.

CRA scope / 15

Does Internally Developed Software Fall Under the CRA?

Understand when internally developed or in-house software falls within Cyber Resilience Act scope, including internal use, external supply, group companies, manufacturer status and later commercial distribution.

READ GUIDE
CRA scope / 16

When Is Software Considered Placed on the EU Market?

Understand when software is placed on the Union market under the Cyber Resilience Act, including first making available, digital distribution, free downloads, commercial activity, software versions and testing releases.

READ GUIDE
CRA scope / 17

Does Free Software Fall Within CRA Scope?

Understand when free software falls within the Cyber Resilience Act, including free-of-charge commercial software, free and open-source software, monetisation, commercial activity and open-source software stewards.

READ GUIDE
CRA reporting / Pillar

Cyber Resilience Act Vulnerability and Incident Reporting Requirements

A practical guide to the Cyber Resilience Act reporting rules for actively exploited vulnerabilities and severe product-security incidents, including the 24-hour, 72-hour and final-report stages.

READ GUIDE
CRA reporting / 01

What Must Manufacturers Report Under Article 14 of the CRA?

Understand the two mandatory Article 14 reporting triggers for manufacturers, the information required at the 24-hour, 72-hour and final-report stages, and the related user-notification duty.

READ GUIDE
CRA reporting / 02

What Is an Actively Exploited Vulnerability Under the CRA?

Understand the Cyber Resilience Act definition of an actively exploited vulnerability, the role of reliable evidence and malicious exploitation, and how it differs from a vulnerability that is merely exploitable.

READ GUIDE
Essential cybersecurity requirements / Pillar

CRA Annex I Essential Cybersecurity Requirements Explained

A practical guide to the Cyber Resilience Act Annex I essential cybersecurity requirements, including product-security properties, vulnerability handling, risk assessment, implementation evidence and lifecycle obligations.

READ GUIDE
Essential cybersecurity requirements / 01

CRA Requirements for Risk-Appropriate Product Security

Understand the CRA requirement to design, develop and produce products with digital elements with an appropriate level of cybersecurity based on the risks, and how to translate that rule into product controls and evidence.

READ GUIDE
Essential cybersecurity requirements / 02

CRA Rules on Known Exploitable Vulnerabilities

Understand the CRA Annex I rule that products with digital elements should be made available on the market without known exploitable vulnerabilities, including its relationship to risk assessment, components, release gates and vulnerability handling.

READ GUIDE
CRA product classification / Pillar

Important and Critical Products Under the Cyber Resilience Act

Understand how the Cyber Resilience Act classifies important and critical products with digital elements, how the core-functionality test works, and why classification changes the available conformity assessment route.

READ GUIDE
CRA product classification / 01

What Is an Important Product With Digital Elements?

Learn what an important product with digital elements means under Article 7 of the Cyber Resilience Act, how the core-functionality test works, and how Annex III classification affects conformity assessment.

READ GUIDE
CRA product classification / 02

CRA Important Products Class I Explained

Understand CRA Important Products Class I, the Annex III categories, the core-functionality test, and when a Class I product can use internal control or needs a stricter conformity assessment procedure.

READ GUIDE
CRA reporting / 03

What Is a Severe Incident Under the Cyber Resilience Act?

Understand when an incident is considered severe under Article 14 of the Cyber Resilience Act, including impacts on security properties, sensitive functions and malicious code.

READ GUIDE
CRA reporting / 04

Understanding the CRA 24-Hour Early Warning

Understand the Cyber Resilience Act 24-hour early-warning requirement for actively exploited vulnerabilities and severe incidents, including timing, minimum information and manufacturer awareness.

READ GUIDE
CRA reporting / 05

Understanding the CRA 72-Hour Notification

Understand what manufacturers must provide in the Cyber Resilience Act 72-hour notification for actively exploited vulnerabilities and severe incidents and how it differs from the 24-hour warning.

READ GUIDE