
Creating an SBOM under the CRA
What the regulation actually requires, how much depth is sufficient, and why the sourcing process — not the tool — determines compliance. An SBOM (Software

Significant change makes you the manufacturer through retrofit
Anyone who substantially modifies or retrofits a machine is quickly considered the manufacturer, with CE marking and conformity obligations. This explains when that applies and

Secure development lifecycle and CRA conformity
The CRA requires a structured development process rather than a final pentest. What an SDL must do and how it proves CRA conformity. The Cyber

ENISA secure by design and default playbook published
The ENISA Secure by Design and Default Playbook translates 22 security principles into checklists and release gates and maps them to Annex I of the

Safety Integrity Level (SIL) vs security level (SL)
The Safety Integrity Level can be summed across subsystems, the Security Level Capability cannot. This explains why SIL and SL-C follow different logic. The Safety

CRA for internal machines and software — when does the regulation apply?
Internally developed products do not automatically fall under the CRA, but in many cases they do. This article explains where the boundary for placing products

CRA guidance of the European Commission and what the new guidelines clarify for manufacturers
Support period, changes, spare parts, cloud connectivity — the Commission’s CRA guidance answers questions that have been open in mechanical and plant engineering for months.

Implement machinery regulation and CRA together
The Machinery Regulation and the Cyber Resilience Act apply in parallel to connected machines. Manufacturers should address both sets of requirements as a single project

When is IEC 62443 certification worthwhile?
Mandatory or voluntary? We explain when IEC 62443 certification is truly useful for manufacturers, what 62443-4-1 achieves, and how to get started. An IEC 62443

Implement machinery regulation and CRA together
The machinery regulation and the CRA apply in parallel to connected machines. Manufacturers should address both sets of requirements as a single project instead of

Plan CRA budget in time
The Cyber Resilience Act applies from December 2027. Including CRA effort in current budget planning avoids costly follow-up demands later. The CRA budget is driven

When is IEC 62443 certification worthwhile
Mandatory or voluntary? We explain when IEC 62443 certification is genuinely useful for manufacturers, what 62443-4-1 provides and how to get started. Eine IEC 62443

Creating an SBOM under the CRA — obligation, format and practice
What the CRA actually requires for SBOMs, how deep they must go and why the sourcing process, not the tool, determines compliance. Eine SBOM (Software

Implement CRA reporting process step by step
How CRA vulnerability reporting works in practice — SRP submission, CSIRT follow-up and user notification step by step. The reporting process of the Cyber Resilience

IEC 62443 security level finding the right level
Security levels in IEC 62443 are not a one-size-fits-all product attribute. The deployment context determines them and SL 1 through SL 4 have different implications

CRA standards are delayed — what manufacturers must do now
The harmonized standards for the Cyber Resilience Act will be ready later than planned. This explains what the new deadlines mean for your CRA preparation