Articles
In-depth articles on connected-product security and on the Cyber Resilience Act. One every two to three weeks. RSS.
Coordinated vulnerability disclosure: the channel the CRA requires you to keep open
The reporting obligations towards the authorities are now applicable, but they are half of the circuit. Annex I, Part II demands the other half: a public channel for receiving vulnerability reports, with a policy, a point of contact and a process behind it. It costs little to set up, and there is a standard for almost everything.
The CRA for software makers: the regulation is not only for people who solder boards
The most common misconception about the CRA is that it addresses device manufacturers. Software sold as a product is in. Pure SaaS is out, with one exception that catches a lot of people. And 'free of charge' does not mean 'non-commercial'.
What automotive already learnt, and the rest of industry will learn by 2027
The automotive sector was the first forced to treat cybersecurity as a product property across the life cycle, with UNECE R155/R156 and ISO/SAE 21434. Vehicles are outside the CRA precisely because of this, and it is also why they serve as a preview.
CRA and RED: the radio-equipped device now lives under two regimes
Since August 2025, any radio equipment connected to the internet has had to meet the RED's cybersecurity requirements. The CRA will replace them, but until December 2027 the two regimes coexist, and work done under one does not automatically count under the other.
The support period: the most expensive promise the CRA makes you make
The CRA obliges every manufacturer to declare for how long it supports the product: as a rule, at least five years. It is an engineering, contracts and supplier decision disguised as a field on a form.
Classifying the product under the CRA: the decision that sets the cost of everything else
Default, important class I, important class II or critical. The product's category determines whether conformity is a self-assessment or a notified body, and the difference is measured in tens of thousands of euros and months of calendar.
The 24h and 72h reports: how the obligation arriving on 11 September works
From 11 September 2026, a manufacturer who learns of an actively exploited vulnerability in its product has 24 hours for the first alert. What gets reported, to whom, through where, and what to prepare beforehand.
SBOM for embedded firmware: what the CRA requires and how to generate one without lying
The software bill of materials the CRA demands is not written by hand. For firmware, the only credible SBOM comes out of the build system, and binary scanning serves for what we did not build ourselves.