
CRA who is responsible for vulnerabilities and SBOM
Which obligations regarding vulnerability handling and SBOM apply to manufacturers, importers and distributors under the CRA? Explained with a machine building example and an illustration.

CRA implementation act makes BSI central market surveillance authority
The CRA implementation act designates the BSI as the market surveillance and notifying authority for the Cyber Resilience Regulation in Germany. Exactly this point is

Harmonized standards for the CRA EN 40000 ETSI and EN 50770
Overview of the EN 40000 series, ETSI EN 304 6xx and EN 50770: structure, status and what they mean for manufacturers under the Cyber Resilience

EU publishes answers to frequently asked questions on the CRA
First official FAQ document on the CRA is now available. The European Commission clarifies key questions on scope, manufacturer obligations and implementation across 66 pages.

The Cyber Resilience Act deadlines at a glance
The Cyber Resilience Act (CRA) is now official. All key deadlines, requirements and action areas for companies at a glance. What does the CRA mean

What is the Cloud and AI Development Act?
The Cloud and AI Development Act aims to strengthen Europe’s cloud and AI ecosystem. Overview of Union Assurance Levels, procurement obligations and timetable. Why did

Maritime cybersecurity IACS UR E26 & E27 explained
Basics of maritime cybersecurity and an analysis of the IACS UR E26 and E27 standards, including how they fit into the EU legal framework. The

NIS 2, CRA and CSA explained
Overview of NIS 2, the Cyber Resilience Act (CRA) and the Cybersecurity Act (CSA). Covers the scopes, objectives and connections between the EU’s main cyber

IEC 62443 security level explained – implementation guide
Learn everything about the security levels for systems and components in IEC 62443, from basics to implementation for manufacturers. Security levels (SL) in IEC 62443

CRA & SBOM what tools cannot detect
SBOM scanners only detect known components, while firmware in purchased parts often remains invisible. The CRA, however, requires a complete documented list of components. What

TARA, threat model and risk assessment compared
Terms around risks, threats and threat analysis cause confusion. This overview shows what the CRA, IEC 62443 and EN 40000 require. Key points in brief

TARA, threat model and risk assessment compared
Terms around risks, threats and threat analysis cause confusion. This overview shows what the CRA, IEC 62443 and EN 40000 require. Key points Confusion does

MDR cybersecurity reporting obligations — EU closes CRA gap
The EU proposal COM(2025) 1023 introduces CRA-like reporting obligations for cybersecurity of medical devices and IVDs, requiring reporting via Eudamed to member-state CSIRTs and ENISA.

RED Delegated Act repeal and transition to CRA 2027
The repeal of Regulation 2022/30 marks the transition from the RED Delegated Act to the CRA. The RED Delegated Act remains applicable until 11 December

Penetration tests for mechanical engineering
How targeted penetration tests secure industrial systems. Methods, requirements and best practices for machine builders, including CRA, IEC 62443 and safety aspects. Contents Attacks on

How the new EU Machinery Regulation makes cybersecurity a safety requirement
The EU Machinery Regulation (EU) 2023/1230 replaces the Machinery Directive on 20 January 2027, making cybersecurity a legal safety requirement for machinery for the first time.