Guides to the Cyber Resilience Act
What the regulation asks for, in plain language, with the wording quoted so you can check every statement against the text yourself. 11 guides, and more as we work through them.
Scope
Reporting
CRA reporting deadlines, and the two clocks people get wrong
Two separate report tracks, not one. Six submissions, four deadlines, and the duty to tell your users as well.
Which CSIRT do I report to under the CRA?
It is not where your company is registered. The rule, the cascade for non-EU manufacturers, and a worksheet.
Scope and risk
CRA penalties and enforcement
Article 64 sets three fine ceilings, not one. It also switches the largest one off entirely for micro and small manufacturers in one specific situation — which almost nobody writing about this mentions.
Do I need a notified body under the CRA?
Most products sit in the default category and the manufacturer signs off their own conformity. Two lists decide whether that is you, and they are short.
CRA vs NIS2: which one applies to you
They overlap in the mind and almost nowhere in the text. The CRA attaches to a product; NIS2 attaches to an organisation in a listed sector. Plenty of businesses get both, and a few get neither.
Documents
What the CRA technical file has to contain
The eight points of Annex VII in plain language, what evidence each one needs, and the two that trip people up.
The CRA's three ten-year retention duties
Article 13 sets three separate ten-year duties running on three different clocks. Most manufacturers are tracking none of them.
What the CRA actually requires of your SBOM
The regulation asks for top-level dependencies, in a format it has not yet specified, and does not require you to publish it. Almost everything sold to solve this exceeds the bar.
The EU declaration of conformity under the CRA
The shortest document the regulation asks for, and the one that carries the most weight. Annex V is mostly transcription — the risk is in what signing it means.
The information you must ship with the product
The forgotten fifth document. Nine points of user information, a ten-year commitment to a URL, and an SBOM clause that is conditional rather than mandatory.