Cyber Resilience Act resources
Page 6 of 12
Showing resources 76 to 90 of 174.
CRA Requirements for Protecting Stored and Transmitted Data
Understand how the Cyber Resilience Act applies confidentiality and integrity requirements to stored and transmitted data, including encryption, authentication, key management, data flows and verification evidence.
READ GUIDE Essential cybersecurity requirements / 08CRA Requirements for Data Minimisation
Understand the Cyber Resilience Act data-minimisation requirement, including how manufacturers can determine which personal and other data are adequate, relevant and necessary for the intended purpose of a product.
READ GUIDE CRA product classification / 09How the CRA Treats Firewalls
Understand how firewalls are classified under the Cyber Resilience Act, which network and application firewall products fall within Annex III Class II, and why firewall classification requires a stricter conformity assessment route.
READ GUIDE CRA product classification / 10How the CRA Treats VPN Products
Understand how VPN products are classified under the Cyber Resilience Act, which VPN clients, servers and gateways fall within Annex III Class I, and how VPN product classification differs from a VPN interface.
READ GUIDE CRA product classification / 11How the CRA Treats Routers and Modems
Understand how routers, internet modems and related switches are classified under the Cyber Resilience Act, which products fall within Annex III Class I, and how integrated security functions affect classification.
READ GUIDE CRA reporting / 12Using an Assigned Representative for CRA Reporting
Understand how Primary and Secondary Assigned Representatives use the CRA Single Reporting Platform, including notification access, updates, manufacturer associations, drafts and reporting continuity.
READ GUIDE CRA reporting / 13What Are Particularly Exceptional Circumstances Under the CRA?
Understand the particularly exceptional circumstances mechanism under Article 16 of the Cyber Resilience Act, including the three PEC conditions, the 72-hour AEV notification and delayed dissemination.
READ GUIDE CRA reporting / 14What Happens if the CRA Reporting Platform Is Unavailable?
Understand what manufacturers should do if the CRA Single Reporting Platform is temporarily unavailable, including direct CSIRT communication and the requirement to submit through the SRP after service is restored.
READ GUIDE Essential cybersecurity requirements / 09CRA Availability and Resilience Requirements
Understand the Cyber Resilience Act requirements for protecting the availability of essential and basic product functions, maintaining resilience after incidents, mitigating denial-of-service attacks and limiting negative effects on other devices and networks.
READ GUIDE Essential cybersecurity requirements / 10CRA Requirements for Limiting Attack Surfaces
Understand the Cyber Resilience Act requirement to design, develop and produce products with digital elements so that attack surfaces are limited, including external interfaces, unnecessary services, privileges and exposed functionality.
READ GUIDE Essential cybersecurity requirements / 11CRA Requirements for Reducing the Impact of Security Incidents
Understand the Cyber Resilience Act requirement to reduce the impact of security incidents through appropriate exploitation-mitigation mechanisms and techniques, including isolation, least privilege, sandboxing and defence in depth.
READ GUIDE CRA product classification / 12How the CRA Treats Operating Systems
Understand how operating systems are classified under the Cyber Resilience Act, which real-time, general-purpose and special-purpose operating systems fall within Annex III Class I, and how classification affects conformity assessment.
READ GUIDE CRA product classification / 13How the CRA Treats Hypervisors
Understand how hypervisors are classified under the Cyber Resilience Act, which bare-metal, hosted and hybrid hypervisors fall within Annex III Class II, and why they require a stricter conformity assessment route.
READ GUIDE CRA product classification / 14How the CRA Treats Industrial Automation Products
Understand how the Cyber Resilience Act applies to industrial automation hardware and software, why industrial automation is not a standalone CRA product class, and how individual products should be screened against Annex III and Annex IV.
READ GUIDE Essential cybersecurity requirements / 12CRA Security Logging Requirements
Understand the Cyber Resilience Act security logging requirement for recording relevant internal activity, including access to and modification of data, services and functions, while managing sensitive information and the required user opt-out mechanism.
READ GUIDE