Cyber Resilience Act Blog

Analysis and practical guidance on the EU Cyber Resilience Act. Regulation explainers, SBOM tooling, vulnerability workflows, and ENISA reporting, written for manufacturers, importers, and distributors.

Compliance

CRA Guidance July 2026: The Edge Cases, Worked Through

When does a component reclassify your product? When does a spare part stop being one? The Commission's July 2026 CRA guidance, explained with worked examples.

Vulnerability Management

ENISA on Frontier AI: 5 Consequences for the CRA

ENISA's July 2026 frontier AI paper: exploitation at machine speed. 5 consequences for Cyber Resilience Act manufacturers, from CVD floods to patch diffing.

Stay in the loop

Get notified when we publish new articles about CRA compliance and product security.