ENISA's Secure by Design Playbook: A CRA Guide
ENISA's Secure by Design and Default Playbook (final v1.0, July 2026) turns CRA rules into 22 practical checklists for SMEs, now also on GitHub.
Analysis and practical guidance on the EU Cyber Resilience Act. Regulation explainers, SBOM tooling, vulnerability workflows, and ENISA reporting, written for manufacturers, importers, and distributors.
ENISA's Secure by Design and Default Playbook (final v1.0, July 2026) turns CRA rules into 22 practical checklists for SMEs, now also on GitHub.
Archive of the March 2026 CRA consultation draft: 9 clarifications on SaaS, legacy products, open source, and reporting. The July draft now supersedes it.
Generate a firmware SBOM using Yocto, Buildroot, EMBA, or Syft. ENISA vulnerability reporting starts September 11, 2026. Step-by-step workflows for CRA compliance.
CSA2 is still a proposal. COM(2026) 11 final would reshape cybersecurity certification, ICT supply chains and ENISA powers.
CRA playbook for companies that manufacture, import and distribute: role mapping, obligation stacking, vulnerability routing, penalties and conflict points.
Set up security.txt at /.well-known/security.txt: Contact, Expires, a copyable example and the CRA technical file link.
Get notified when we publish new articles about CRA compliance and product security.