Guides
The Regulation, in plain language.
Written for people who build and ship software, not for lawyers. Every statement about the Regulation carries a link to its source, and anything we have not checked against the primary text ourselves says so.
- 01
Does the Cyber Resilience Act apply to my software?
A scope test for the EU Cyber Resilience Act: who counts as a manufacturer, what falls outside, and why shipping an agent pulls a SaaS company back in.
3 min - 02
CRA reporting deadlines: 24 hours, 72 hours, 14 days
What the Cyber Resilience Act reporting clocks measure, when they start, why they run in parallel, and what to have ready before the obligation begins.
3 min - 03
What the CRA expects from an SBOM
Formats, depth, package URLs and where to generate it. A practical read on the software bill of materials the Cyber Resilience Act asks manufacturers for.
3 min - 04
CRA penalties: the three tiers and the one people skim
Ceilings, shares of turnover and what each tier covers under the Cyber Resilience Act, plus the costs that arrive long before any regulator does.
3 min - 05
How to write a coordinated vulnerability disclosure policy
What a CVD policy has to contain, the two sentences that matter most, a timeline you can keep, and why security.txt is worth nine lines.
3 min - 06
The CRA timeline, and the date that catches small vendors
Every applicable date of the Cyber Resilience Act in one table, why the reporting date is harder than full application, and a schedule that works backwards.
2 min
This material is generated from your own product data and public sources. It is not legal advice. Have a qualified adviser review your compliance documentation before you rely on it.