<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>folhas.io (English)</title><description>Secure by design for manufacturers of connected products. Cyber Resilience Act preparation, grounded in offensive security and in automotive product life cycles.</description><link>https://folhas.io</link><language>en</language><item><title>Coordinated vulnerability disclosure: the channel the CRA requires you to keep open</title><link>https://folhas.io/en/articles/08-coordinated-disclosure</link><guid isPermaLink="true">https://folhas.io/en/articles/08-coordinated-disclosure</guid><description>The reporting obligations towards the authorities are now applicable, but they are half of the circuit. Annex I, Part II demands the other half: a public channel for receiving vulnerability reports, with a policy, a point of contact and a process behind it. It costs little to set up, and there is a standard for almost everything.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate></item><item><title>004 · The day the countdown reached zero</title><link>https://folhas.io/en/logbook/004-the-day-the-countdown-reached-zero</link><guid isPermaLink="true">https://folhas.io/en/logbook/004-the-day-the-countdown-reached-zero</guid><description>The reporting obligations of Article 14 became applicable today. What changes for those who already have products on the market, what we did with the advance notice, and why the OTA entry waits one more round.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate></item><item><title>The CRA for software makers: the regulation is not only for people who solder boards</title><link>https://folhas.io/en/articles/07-cra-for-software-makers</link><guid isPermaLink="true">https://folhas.io/en/articles/07-cra-for-software-makers</guid><description>The most common misconception about the CRA is that it addresses device manufacturers. Software sold as a product is in. Pure SaaS is out, with one exception that catches a lot of people. And &apos;free of charge&apos; does not mean &apos;non-commercial&apos;.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item><item><title>003 · From prototype to product: the plan, the sequence and what it costs</title><link>https://folhas.io/en/logbook/003-from-prototype-to-product</link><guid isPermaLink="true">https://folhas.io/en/logbook/003-from-prototype-to-product</guid><description>The audit from entry 002 turned into a work plan. Four phases, what goes into each one, and where the money gets spent. A good part of it is not code.</description><pubDate>Wed, 05 Aug 2026 00:00:00 GMT</pubDate></item><item><title>What automotive already learnt, and the rest of industry will learn by 2027</title><link>https://folhas.io/en/articles/06-what-automotive-already-learnt</link><guid isPermaLink="true">https://folhas.io/en/articles/06-what-automotive-already-learnt</guid><description>The automotive sector was the first forced to treat cybersecurity as a product property across the life cycle, with UNECE R155/R156 and ISO/SAE 21434. Vehicles are outside the CRA precisely because of this, and it is also why they serve as a preview.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>002 · The prototype meets the regulation: we audited our own firmware</title><link>https://folhas.io/en/logbook/002-the-prototype-meets-the-regulation</link><guid isPermaLink="true">https://folhas.io/en/logbook/002-the-prototype-meets-the-regulation</guid><description>We applied to Aerodry, our prototype with two years of real operation, the same CRA analysis we offer clients. We describe the nine flaws with direct consequence. This is the report.</description><pubDate>Wed, 29 Jul 2026 00:00:00 GMT</pubDate></item><item><title>CRA and RED: the radio-equipped device now lives under two regimes</title><link>https://folhas.io/en/articles/05-cra-and-red</link><guid isPermaLink="true">https://folhas.io/en/articles/05-cra-and-red</guid><description>Since August 2025, any radio equipment connected to the internet has had to meet the RED&apos;s cybersecurity requirements. The CRA will replace them, but until December 2027 the two regimes coexist, and work done under one does not automatically count under the other.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The support period: the most expensive promise the CRA makes you make</title><link>https://folhas.io/en/articles/04-the-support-period</link><guid isPermaLink="true">https://folhas.io/en/articles/04-the-support-period</guid><description>The CRA obliges every manufacturer to declare for how long it supports the product: as a rule, at least five years. It is an engineering, contracts and supplier decision disguised as a field on a form.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>001 · Starting point: the decisions before the product</title><link>https://folhas.io/en/logbook/001-starting-point</link><guid isPermaLink="true">https://folhas.io/en/logbook/001-starting-point</guid><description>First entry in the logbook of preparing our agri-IoT product for the CRA. Where we stand, what we have already decided, what we still don&apos;t know.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Classifying the product under the CRA: the decision that sets the cost of everything else</title><link>https://folhas.io/en/articles/03-classifying-the-product</link><guid isPermaLink="true">https://folhas.io/en/articles/03-classifying-the-product</guid><description>Default, important class I, important class II or critical. The product&apos;s category determines whether conformity is a self-assessment or a notified body, and the difference is measured in tens of thousands of euros and months of calendar.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The 24h and 72h reports: how the obligation arriving on 11 September works</title><link>https://folhas.io/en/articles/02-the-24h-and-72h-reports</link><guid isPermaLink="true">https://folhas.io/en/articles/02-the-24h-and-72h-reports</guid><description>From 11 September 2026, a manufacturer who learns of an actively exploited vulnerability in its product has 24 hours for the first alert. What gets reported, to whom, through where, and what to prepare beforehand.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate></item><item><title>SBOM for embedded firmware: what the CRA requires and how to generate one without lying</title><link>https://folhas.io/en/articles/01-sbom-for-embedded-firmware</link><guid isPermaLink="true">https://folhas.io/en/articles/01-sbom-for-embedded-firmware</guid><description>The software bill of materials the CRA demands is not written by hand. For firmware, the only credible SBOM comes out of the build system, and binary scanning serves for what we did not build ourselves.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>