Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 6 of 12

Showing resources 76 to 90 of 174.

Essential cybersecurity requirements / 07

CRA Requirements for Protecting Stored and Transmitted Data

Understand how the Cyber Resilience Act applies confidentiality and integrity requirements to stored and transmitted data, including encryption, authentication, key management, data flows and verification evidence.

READ GUIDE
Essential cybersecurity requirements / 08

CRA Requirements for Data Minimisation

Understand the Cyber Resilience Act data-minimisation requirement, including how manufacturers can determine which personal and other data are adequate, relevant and necessary for the intended purpose of a product.

READ GUIDE
CRA product classification / 09

How the CRA Treats Firewalls

Understand how firewalls are classified under the Cyber Resilience Act, which network and application firewall products fall within Annex III Class II, and why firewall classification requires a stricter conformity assessment route.

READ GUIDE
CRA product classification / 10

How the CRA Treats VPN Products

Understand how VPN products are classified under the Cyber Resilience Act, which VPN clients, servers and gateways fall within Annex III Class I, and how VPN product classification differs from a VPN interface.

READ GUIDE
CRA product classification / 11

How the CRA Treats Routers and Modems

Understand how routers, internet modems and related switches are classified under the Cyber Resilience Act, which products fall within Annex III Class I, and how integrated security functions affect classification.

READ GUIDE
CRA reporting / 12

Using an Assigned Representative for CRA Reporting

Understand how Primary and Secondary Assigned Representatives use the CRA Single Reporting Platform, including notification access, updates, manufacturer associations, drafts and reporting continuity.

READ GUIDE
CRA reporting / 13

What Are Particularly Exceptional Circumstances Under the CRA?

Understand the particularly exceptional circumstances mechanism under Article 16 of the Cyber Resilience Act, including the three PEC conditions, the 72-hour AEV notification and delayed dissemination.

READ GUIDE
CRA reporting / 14

What Happens if the CRA Reporting Platform Is Unavailable?

Understand what manufacturers should do if the CRA Single Reporting Platform is temporarily unavailable, including direct CSIRT communication and the requirement to submit through the SRP after service is restored.

READ GUIDE
Essential cybersecurity requirements / 09

CRA Availability and Resilience Requirements

Understand the Cyber Resilience Act requirements for protecting the availability of essential and basic product functions, maintaining resilience after incidents, mitigating denial-of-service attacks and limiting negative effects on other devices and networks.

READ GUIDE
Essential cybersecurity requirements / 10

CRA Requirements for Limiting Attack Surfaces

Understand the Cyber Resilience Act requirement to design, develop and produce products with digital elements so that attack surfaces are limited, including external interfaces, unnecessary services, privileges and exposed functionality.

READ GUIDE
Essential cybersecurity requirements / 11

CRA Requirements for Reducing the Impact of Security Incidents

Understand the Cyber Resilience Act requirement to reduce the impact of security incidents through appropriate exploitation-mitigation mechanisms and techniques, including isolation, least privilege, sandboxing and defence in depth.

READ GUIDE
CRA product classification / 12

How the CRA Treats Operating Systems

Understand how operating systems are classified under the Cyber Resilience Act, which real-time, general-purpose and special-purpose operating systems fall within Annex III Class I, and how classification affects conformity assessment.

READ GUIDE
CRA product classification / 13

How the CRA Treats Hypervisors

Understand how hypervisors are classified under the Cyber Resilience Act, which bare-metal, hosted and hybrid hypervisors fall within Annex III Class II, and why they require a stricter conformity assessment route.

READ GUIDE
CRA product classification / 14

How the CRA Treats Industrial Automation Products

Understand how the Cyber Resilience Act applies to industrial automation hardware and software, why industrial automation is not a standalone CRA product class, and how individual products should be screened against Annex III and Annex IV.

READ GUIDE
Essential cybersecurity requirements / 12

CRA Security Logging Requirements

Understand the Cyber Resilience Act security logging requirement for recording relevant internal activity, including access to and modification of data, services and functions, while managing sensitive information and the required user opt-out mechanism.

READ GUIDE