Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 8 of 12

Showing resources 106 to 120 of 174.

Open source software and the CRA / 02

What Is an Open Source Software Steward?

Understand the Cyber Resilience Act definition of an open-source software steward, the sustained-support and commercial-intention tests, and the cybersecurity obligations created by Article 24.

READ GUIDE
Secure product development / 03

CRA Security Requirements During Product Design

Understand how Cyber Resilience Act requirements should influence product design, including cybersecurity risk assessment, architecture, attack surfaces, trust boundaries, interfaces, components and verification planning.

READ GUIDE
Secure product development / 04

Threat Modelling for CRA Readiness

Learn how threat modelling can support Cyber Resilience Act readiness by connecting product context, attack paths, trust boundaries and security controls to the Article 13 cybersecurity risk assessment.

READ GUIDE
Secure product development / 05

Defining Product Security Requirements

Learn how to define product security requirements for CRA readiness by translating cybersecurity risks and Annex I outcomes into measurable engineering requirements, ownership and verification criteria.

READ GUIDE
Cybersecurity risk assessment and technical documentation

CRA Cybersecurity Risk Assessment and Technical Documentation

Understand how Cyber Resilience Act cybersecurity risk assessment and technical documentation fit together, including Article 13, Annex I, Article 31, Annex VII, lifecycle updates, evidence and conformity readiness.

READ GUIDE
Cybersecurity risk assessment / 01

How to Perform a CRA Cybersecurity Risk Assessment

A practical step-by-step method for performing a Cyber Resilience Act cybersecurity risk assessment, from defining the product boundary and intended use through threat analysis, Annex I mapping, risk treatment and evidence maintenance.

READ GUIDE
Cybersecurity risk assessment / 02

What Should a CRA Risk Assessment Contain?

Understand the minimum Cyber Resilience Act cybersecurity risk assessment content required by Article 13 and the practical records manufacturers can add for stronger risk, Annex I and technical-documentation traceability.

READ GUIDE
Open source software and the CRA / 03

What Does Commercial Activity Mean for Open Source Software Under the CRA?

Understand what commercial activity means for free and open-source software under the Cyber Resilience Act, including monetisation, financial support, regular releases, downstream integration and non-profit development.

READ GUIDE
Open source software and the CRA / 04

When Is Free and Open Source Software Outside CRA Manufacturer Obligations?

Understand when free and open-source software can fall outside CRA manufacturer obligations, including non-monetised development, contributors, non-profit projects, upstream components and the separate steward regime.

READ GUIDE
Open source software and the CRA / 05

CRA Responsibilities for Open Source Foundations

Understand how open-source foundations should analyse their Cyber Resilience Act role, including steward status, non-profit development, cybersecurity policies, vulnerability handling, reporting and downstream commercial use.

READ GUIDE
Secure product development / 06

Secure Coding Practices for CRA Compliance

Understand how secure coding practices support Cyber Resilience Act compliance, including coding standards, input validation, code review, SAST, dependency analysis, secret handling and negative testing.

READ GUIDE
Secure product development / 07

Security Reviews During Software Development

Learn how security reviews can support CRA secure development, including architecture review, threat-model review, code review, dependency review, change review and release security decisions.

READ GUIDE
Secure product development / 08

CRA Security Testing Requirements

Understand Cyber Resilience Act security testing requirements, including effective and regular testing, risk-based test scope, negative testing, regression testing, test reports and conformity evidence.

READ GUIDE
Cybersecurity risk assessment / 03

Identifying Intended Product Use Under the CRA

Learn how manufacturers can define and document intended product use under the Cyber Resilience Act, including intended purpose, users, functions, operating context, security environment, assumptions and technical documentation.

READ GUIDE
Cybersecurity risk assessment / 04

Identifying Reasonably Foreseeable Misuse

Understand how reasonably foreseeable use and misuse fit into the Cyber Resilience Act cybersecurity risk assessment, including predictable human behaviour, technical interactions, deployment conditions and user information.

READ GUIDE