Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 5 of 12

Showing resources 61 to 75 of 174.

Essential cybersecurity requirements / 04

CRA Authentication Requirements

Understand the Cyber Resilience Act requirements for protection from unauthorised access, including authentication, identity management, access management, authorisation, access reporting and product-specific evidence.

READ GUIDE
Essential cybersecurity requirements / 05

CRA Confidentiality Requirements

Understand the Cyber Resilience Act requirements for protecting the confidentiality of stored, transmitted and otherwise processed data, including encryption, key management, data exposure and product-specific evidence.

READ GUIDE
CRA product classification / 03

CRA Important Products Class II Explained

Understand CRA Important Products Class II, the four Annex III categories, the core-functionality test, and the stricter conformity assessment procedures required by Article 32.

READ GUIDE
CRA product classification / 04

What Is a Critical Product Under the CRA?

Understand what a critical product with digital elements means under the Cyber Resilience Act, which products Annex IV currently lists, and how critical classification changes conformity assessment and certification.

READ GUIDE
CRA product classification / 05

How to Determine a Product's CRA Classification

Use a practical process to determine whether a CRA-covered product falls into the default category, Important Product Class I, Important Product Class II, or an Annex IV critical-product category.

READ GUIDE
CRA reporting / 06

CRA Final Reporting Requirements for Vulnerabilities

Understand the Cyber Resilience Act final-report requirements for actively exploited vulnerabilities, including the 14-day deadline, required vulnerability information and corrective-measure details.

READ GUIDE
CRA reporting / 07

CRA Final Reporting Requirements for Severe Incidents

Understand the Cyber Resilience Act final-report requirements for severe product-security incidents, including the one-month deadline, detailed incident description, likely root cause and mitigation measures.

READ GUIDE
CRA reporting / 08

How the CRA Single Reporting Platform Works

Understand how the Cyber Resilience Act Single Reporting Platform works, including ENISA's role, CSIRT selection, notification routing, reporting stages and manufacturer responsibilities.

READ GUIDE
CRA product classification / 06

How the CRA Treats Identity Management Software

Understand how the Cyber Resilience Act treats identity management systems, privileged access management software, authentication products and related access-control technologies under Annex III Class I.

READ GUIDE
CRA product classification / 07

How the CRA Treats Password Managers

Understand how password managers are classified under the Cyber Resilience Act, which password-storage and management products fall within Annex III Class I, and how classification affects conformity assessment.

READ GUIDE
CRA product classification / 08

How the CRA Treats Network Management Systems

Understand how network management systems are classified under the Cyber Resilience Act, which monitoring and configuration functions fall within Annex III Class I, and how classification affects conformity assessment.

READ GUIDE
CRA reporting / 09

How to Register for the CRA Single Reporting Platform

A practical guide to registering for the CRA Single Reporting Platform, including EU Login, MFA, Primary and Secondary Assigned Representatives, CSIRT selection and manufacturer validation.

READ GUIDE
CRA reporting / 10

How to Determine the Correct CSIRT for CRA Reporting

Learn how Article 14(7) determines the CSIRT designated as coordinator for CRA reporting, including the main-establishment test and the fallback rules for manufacturers without an EU main establishment.

READ GUIDE
CRA reporting / 11

CRA Reporting for Non-EU Manufacturers

Understand how non-EU manufacturers report actively exploited vulnerabilities and severe incidents under the Cyber Resilience Act, including Article 14(7) CSIRT routing and SRP responsibilities.

READ GUIDE
Essential cybersecurity requirements / 06

CRA Integrity Requirements

Understand the Cyber Resilience Act requirements for protecting the integrity of data, commands, programs and configuration against unauthorised manipulation or modification, including corruption reporting and verification evidence.

READ GUIDE