Cyber Resilience Act Blog

Analysis and practical guidance on the EU Cyber Resilience Act. Regulation explainers, SBOM tooling, vulnerability workflows, and ENISA reporting, written for manufacturers, importers, and distributors.

Compliance

ENISA NCAF 2.0: What the 2026 Update Means for CRA

ENISA's NCAF 2.0 (April 2026) is the first update in six years: three new objectives, 871 maturity questions, and explicit CRA references for governments.

Country & Market Guides

ECSMAF v3.0: How ENISA Maps the EU Cybersecurity Market

ENISA's ECSMAF v3.0 defines how the EU categorises its cybersecurity market: the supply-side taxonomy, CRA integration, and what it means for manufacturers.

Stay in the loop

Get notified when we publish new articles about CRA compliance and product security.