Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 7 of 12

Showing resources 91 to 105 of 174.

Essential cybersecurity requirements / 13

CRA Requirements for Security Monitoring

Understand the Cyber Resilience Act security monitoring requirement, including monitoring relevant internal activity, detecting meaningful security conditions, using recorded events and implementing the required user opt-out mechanism.

READ GUIDE
Essential cybersecurity requirements / 14

CRA Requirements for Secure Data Removal

Understand the Cyber Resilience Act requirement to let users securely and easily remove all data and settings permanently, including secure decommissioning, reset distinctions, storage media, cloud data and secure transfer to other products or systems.

READ GUIDE
CRA reporting / 15

Can a CRA Notification Be Corrected or Updated?

Understand when a CRA Single Reporting Platform notification can be corrected or updated, who receives update alerts and when a submitted notification becomes non-editable.

READ GUIDE
CRA reporting / 16

CRA Reporting for Products Placed on the Market Before December 2027

Understand why Article 14 CRA reporting already applies to in-scope products placed on the market before 11 December 2027 and how this differs from the Regulation's wider transitional rules.

READ GUIDE
CRA reporting / 17

How to Build an Internal CRA Incident Escalation Workflow

A practical framework for escalating potential CRA Article 14 events from technical detection to legal classification, 24-hour warning, 72-hour notification, user communication and final reporting.

READ GUIDE
Essential cybersecurity requirements / 15

CRA Requirements for Automatic Security Updates

Understand the Cyber Resilience Act requirements for security updates, including automatic installation where applicable, default-enabled updates, user opt-out, temporary postponement, update notification and secure distribution.

READ GUIDE
Essential cybersecurity requirements / 16

CRA Requirements for Vulnerability Identification

Understand the Cyber Resilience Act requirements for identifying and documenting vulnerabilities and product components, including software bills of materials, dependency visibility, vulnerability intake, testing and product-version tracking.

READ GUIDE
Essential cybersecurity requirements / 17

CRA Requirements for Vulnerability Remediation

Understand the Cyber Resilience Act requirements for addressing and remediating vulnerabilities without delay, including risk-based prioritisation, security updates, secure distribution, vulnerability advisories and remediation evidence.

READ GUIDE
CRA product classification / 15

Why CRA Product Classification Changes Conformity Requirements

Understand why CRA product classification changes the available conformity assessment procedure, including self-assessment for default products, conditional Class I self-assessment, Class II third-party routes and critical-product certification requirements.

READ GUIDE
Secure product development / Pillar

Secure Development Under the Cyber Resilience Act

A practical guide to secure product development under the Cyber Resilience Act, including cybersecurity risk assessment, secure-by-design principles, secure defaults, engineering controls, testing, release gates and lifecycle evidence.

READ GUIDE
Secure product development / 01

What Secure by Design Means Under the CRA

Understand what secure by design means in the Cyber Resilience Act context, how Article 13 moves cybersecurity into product planning and architecture, and how manufacturers can turn risk assessment into engineering decisions.

READ GUIDE
Secure product development / 02

What Secure by Default Means Under the CRA

Understand secure by default as a CRA product-development principle, how Annex I point 2(b) affects initial product behaviour, and how secure defaults should influence design, implementation, testing and release.

READ GUIDE
Essential cybersecurity requirements / 18

How to Map Annex I Requirements to Product Controls

Build a practical Cyber Resilience Act Annex I control matrix that connects legal requirements to cybersecurity risks, product controls, owners, verification methods and technical evidence.

READ GUIDE
Open source software and the CRA

Open Source Software Under the Cyber Resilience Act

Understand how the Cyber Resilience Act treats free and open-source software, manufacturers, open-source software stewards, contributors, commercial activity, vulnerability handling and downstream use.

READ GUIDE
Open source software and the CRA / 01

How the CRA Applies to Open Source Software

Learn when the Cyber Resilience Act applies to open-source software, how commercial activity changes the analysis, and how manufacturers, stewards, contributors and downstream users are treated differently.

READ GUIDE