Points of view to inform your strategy and speed up your decisions: what we see in client work and in our research, written for the people who carry product security in their company.
What CRA compliance costs, and how to budget for it
A first product costs in the order of 100,000€ to bring into Cyber Resilience Act compliance, and much less for those that follow. What manufacturers of every size are spending today, where the money goes, and how to build the budget.
Read the articleWho does what in CRA compliance: building the right support team
Seven types of provider offer CRA support, and they solve very different problems. A buyer’s map of the landscape, and how to combine them.
Read the articleOne technical file for RED and the CRA
The documentation you wrote for RED and EN 18031 is the starting point of your Cyber Resilience Act file. What carries over, what the CRA adds, and how to keep one file for both.
Read the articleAn SBOM is not CRA compliance
The SBOM has become the symbol of Cyber Resilience Act readiness. It is a required input, not a vulnerability management process, and treating it as one creates real compliance risk.
Read the articleThe CRA deadline that matters is not December 2027
Reporting obligations already apply, and products launching in December 2027 are being designed now. Why waiting is the most expensive CRA strategy, and the three things to do first.
Read the articleSMEs and the CRA: closing the gap between aware and ready
ENISA’s first SME survey shows that small manufacturers know the Cyber Resilience Act is coming and are not ready for it. A plan that one person can run, and where tools and outside help fit.
Read the articleFive objectives: a framework to simplify CRA compliance
The Cyber Resilience Act lists requirements. Product teams need a model. How we structure CRA compliance around five objectives and twenty building blocks, and which five to start with.
Read the articleDon't write your first CRA technical file alone
Under the Cyber Resilience Act, the technical documentation is the basis of every conformity assessment. Why the first file is the hardest, and how to get it right once and reuse it.
Read the article