Skip to content

Blog

Practical guides on the Cyber Resilience Act for software manufacturers, SMEs and agencies.

    • Harmonisierte Normen
    • ETSI
    • Konformitätsbewertung

    CRA harmonised standards: status September 2026

    Without standards cited in the Official Journal there is no presumption of conformity. Where CRA standardisation stands and why waiting is not a strategy.

    6 min read

    • ENISA
    • Single Reporting Platform
    • Meldepflicht
    • BSI

    ENISA Single Reporting Platform: how to report under CRA

    Since 11 September 2026 the ENISA platform accepts CRA reports. What the SRP is, how a report flows and what to prepare now.

    6 min read

    • Meldepflicht
    • Selbsttest
    • Incident Response
    • BSI

    10 days to CRA reporting: readiness check

    CRA reporting starts on 11 September. A seven-question self-test – and what to do if a zero-day notice arrives the day after.

    6 min read

    • Checkliste
    • Umsetzung
    • Technische Dokumentation

    CRA compliance checklist: 12 steps

    Prioritised, not exhaustive: what must be in place by 11 September 2026 and what to build by December 2027. 12 steps for manufacturers and agencies.

    6 min read

    • Open Source
    • Supply Chain
    • Open-Source-Steward

    Open source under the CRA: makers, stewards, maintainers

    Non-commercial open source is exempt – but whoever ships it inside a product is responsible for it. What manufacturers, stewards and maintainers need to know.

    6 min read

    • Konformitätsbewertung
    • Annex III
    • Annex IV
    • Maschinenbau

    CRA product categories explained

    Your product category decides whether you may self-assess or need a notified body. An overview with a focus on machinery and IoT.

    6 min read

    • Agenturen
    • Herstellerbegriff
    • Verträge

    CRA for agencies: who is the manufacturer?

    The manufacturer is whoever places a product on the market under their own name. Yet evidence and work often land with the service provider. A guide for agencies.

    6 min read

    • SBOM
    • CycloneDX
    • SPDX
    • CI/CD

    How to create an SBOM for CRA compliance

    The CRA requires a machine-readable software bill of materials. How to generate SBOMs automatically in your pipeline – and put them to work for vulnerability handling.

    6 min read

    • Meldepflicht
    • Art. 14
    • Incident Response

    CRA reporting from 11 Sep 2026: the 24h/72h clock

    Article 14 reporting kicks in 15 months before all other CRA obligations – including for products already sold. How to prepare.

    6 min read

    • Cyber Resilience Act
    • Grundlagen
    • Fristen

    The Cyber Resilience Act explained for software makers

    The CRA makes cybersecurity a condition for EU market access. Which products are in scope, the three dates that matter and where to start.

    6 min read

Join the waitlist

We launch in November. Be the first to get access.