CRA guides
Documentary, sourced, written for software makers — every regulatory date links to the official text.
Is Your Software in Scope of the EU Cyber Resilience Act?
SaaS, open source, plugins, mobile apps: a practical scope check for the EU Cyber Resilience Act (Regulation 2024/2847), with the main exclusions.
6 min read
CRA Self-Assessment (Module A): Who Qualifies, What It Takes
Which products can self-assess CRA conformity under Module A, why harmonised standards matter, and what the technical file must actually contain.
7 min read
CRA Reporting From 11 September 2026: 24h/72h/14-Day Rules
From 11 September 2026, manufacturers must report exploited vulnerabilities and severe incidents to ENISA: the 24h/72h/14-day timeline, explained.
6 min read
The CVD Policy the CRA Requires — and How to Publish One
The Cyber Resilience Act requires a coordinated vulnerability disclosure policy. What it must contain, and how to ship one with security.txt.
5 min read