Independent information resource Product security · EU CRA
RESOURCE LIBRARY

Cyber Resilience Act resources

Page 9 of 14

Showing resources 121 to 135 of 202.

Secure product development / 07

Security Reviews During Software Development

Learn how security reviews can support CRA secure development, including architecture review, threat-model review, code review, dependency review, change review and release security decisions.

READ GUIDE
Secure product development / 08

CRA Security Testing Requirements

Understand Cyber Resilience Act security testing requirements, including effective and regular testing, risk-based test scope, negative testing, regression testing, test reports and conformity evidence.

READ GUIDE
Cybersecurity risk assessment / 03

Identifying Intended Product Use Under the CRA

Learn how manufacturers can define and document intended product use under the Cyber Resilience Act, including intended purpose, users, functions, operating context, security environment, assumptions and technical documentation.

READ GUIDE
Cybersecurity risk assessment / 04

Identifying Reasonably Foreseeable Misuse

Understand how reasonably foreseeable use and misuse fit into the Cyber Resilience Act cybersecurity risk assessment, including predictable human behaviour, technical interactions, deployment conditions and user information.

READ GUIDE
Cybersecurity risk assessment / 05

Documenting Threats and Attack Scenarios

Learn how to document threats and attack scenarios as practical evidence for a Cyber Resilience Act cybersecurity risk assessment, including assets, threat actors, entry points, preconditions, attack paths, consequences and controls.

READ GUIDE
Open source software and the CRA / 06

CRA Responsibilities for Corporate-Sponsored Open Source Projects

Understand how the Cyber Resilience Act treats corporate-sponsored open-source projects, including company funding, employee contributions, commercial intention, steward status and downstream manufacturer responsibilities.

READ GUIDE
Open source software and the CRA / 07

CRA Responsibilities for Individual Open Source Maintainers

Understand how the Cyber Resilience Act treats individual open-source maintainers, including the difference between contributors, maintainers, manufacturers and open-source software stewards.

READ GUIDE
Open source software and the CRA / 08

CRA Reporting Obligations for Open Source Software Stewards

Understand the Cyber Resilience Act reporting obligations for open-source software stewards, including Article 24(3), actively exploited vulnerabilities, severe incidents, the Single Reporting Platform and the 11 December 2027 application date.

READ GUIDE
Secure product development / 09

Penetration Testing and the Cyber Resilience Act

Understand how penetration testing can support Cyber Resilience Act compliance, when it is useful, how it differs from vulnerability scanning and how penetration-test evidence can support CRA security testing.

READ GUIDE
Secure product development / 10

Integrating CRA Controls Into CI/CD Pipelines

Learn how CI/CD pipelines can automate repeatable Cyber Resilience Act security controls, including SAST, dependency checks, secret scanning, security tests, artefact integrity and evidence retention.

READ GUIDE
Secure product development / 11

Security Release Gates for Digital Products

Learn how security release gates can support CRA readiness by preventing product versions from shipping before required security controls, tests, vulnerability reviews and evidence are complete.

READ GUIDE
Cybersecurity risk assessment / 06

Assessing Product Cybersecurity Risk

Learn how to assess product cybersecurity risk under the Cyber Resilience Act using product-specific threat scenarios, attack feasibility, potential impact, existing controls, Annex I requirements and residual risk.

READ GUIDE
Cybersecurity risk assessment / 07

Documenting Risk Treatment Decisions

Learn how to document Cyber Resilience Act cybersecurity risk treatment decisions, including selected controls, rejected alternatives, ownership, residual risk, verification, Annex I mapping and technical evidence.

READ GUIDE
Technical documentation / 08

What Technical Documentation Is Required by the CRA?

Understand the Cyber Resilience Act technical documentation required by Article 31 and Annex VII, including product description, architecture, vulnerability handling, risk assessment, support period, standards, test reports, declaration of conformity and SBOM information.

READ GUIDE
Open source software and the CRA / 09

Open Source Vulnerability Management Under the CRA

Understand how open-source vulnerability management works under the Cyber Resilience Act across stewards, maintainers and downstream manufacturers, including Article 24 policies, vulnerability reporting and remediation.

READ GUIDE