Cyber Resilience Act Guides
Practical guidance on applying the Cyber Resilience Act, based on our experience helping clients implement its requirements.
General guides
EU Cyber Resilience Act Reporting Requirements: Article 14 and the SRP
Understand CRA Article 14 reporting triggers, 24-hour and 72-hour notifications, final reports, CSIRT routing and practical reporting preparation.
From IEC 62443 to EU Cyber Resilience Act Compliance
Use IEC 62443-4-1 and 4-2 evidence to prepare for EU Cyber Resilience Act compliance. Check what an assessment covers, what it supports and what remains.
Guides for US companies
California and Oregon IoT Security Laws and the EU Cyber Resilience Act
Compare California SB 327 and Oregon device-security rules with the EU Cyber Resilience Act. Reuse authentication evidence and find the remaining EU obligations.
Using CMMC and DFARS Evidence for EU Cyber Resilience Act Compliance
How CMMC, DFARS and NIST SP 800-171 evidence can support EU Cyber Resilience Act work for commercial products, with scope limits and separate reporting duties.
US Federal Software and IoT Procurement Evidence for the EU Cyber Resilience Act
Use evidence from US federal software and IoT contracts for the EU Cyber Resilience Act, with current OMB policy, NIST guidance and product gap checks.
From the US Cyber Trust Mark to EU Cyber Resilience Act Compliance
Reuse Cyber Trust Mark testing and product-security evidence for the EU Cyber Resilience Act. Check scope, support periods, reporting and conformity obligations.
From NIST SSDF to EU Cyber Resilience Act Compliance
Use your NIST SSDF practices and evidence to prepare for EU Cyber Resilience Act compliance. Identify reusable work, product-specific gaps and remaining obligations.