Engineering Blog

CVD Portal Engineering

Technical insights on coordinated vulnerability disclosure, CRA compliance, and product security engineering.

Supply Chain Security2026-09-05· 11 min read

Do you need VEX documents for CRA compliance?

The Cyber Resilience Act never uses the word VEX. It still makes exploitability the legal test, and it still requires you to share vulnerability information about third-party components. ENISA surveyed 334 organisations and found 76 percent rate supplier exploitability claims as critical or important. Here are the four statuses, the five justifications, the three competing formats, and how to choose one.

By The CVD Portal Team
CRA Compliance2026-09-04· 10 min read

Does RED DA work count toward CRA compliance?

The RED cybersecurity Delegated Regulation is repealed with effect from 11 December 2027, the day the Cyber Resilience Act applies in full. Test evidence built against EN 18031 carries forward into the CRA technical file. The vulnerability monitoring duty that starts on 11 September 2026 does not, because RED DA never asked for it. Here is what transfers, what does not, and the volume arithmetic that decides your tooling budget.

By The CVD Portal Team
CRA Compliance2026-08-16· 7 min read

ENISA assessment report: the end of SOG-IS, the rise of EUCC, and fixed-time testing for SMEs

ENISA published its 5-year cybersecurity assessment report covering 2021 to 2025. The data confirms the retirement of SOG-IS in February 2026, the operational launch of EUCC with 24 accredited laboratories, and the standardisation of fixed-time SME testing under EN 17640 (FiTCEM). Here is what the numbers mean for manufacturers preparing for the EU Cyber Resilience Act.

By The CVD Portal Team
CRA Compliance2026-08-08· 8 min read

What a CRA maturity score actually predicts

ENISA published its SME Cyber Resilience Maturity Assessment Model on 13 July 2026, and it is explicit that an advanced score is not evidence of CRA compliance. So what is the score for? Maturity measures how consistently your organisation works. Conformity measures whether one product has the evidence behind it. Why an Advanced organisation can still ship a non-conforming product, why a Level 2 team can ship a conforming one, and how to use the score for the thing it is genuinely good at, which is sequencing the work.

By The CRA Portal Team
CRA Compliance2026-08-06· 10 min read

Article 14 applies in five weeks. Run this drill before it does.

On 11 September 2026 the CRA's reporting duties become binding, and the first clock that matters runs for 24 hours from the moment you become aware. Most manufacturers can recite the deadlines and still miss them, because the gap is never knowledge, it is not knowing who files, from which account, to which CSIRT. Here is a walk-through drill that surfaces the gaps while they are still cheap.

By The CVD Portal Team
CRA Compliance2026-07-29· 11 min read

The ETSI EN 304 series: one CRA standard per Annex III product category

Everyone tracking CRA standardisation is watching the horizontal prEN 40000 series. The other half of standardisation request M/606 is 18 vertical standards, EN 304 617 to EN 304 642, one per Annex III product category, and ETSI has public drafts out for most of them. Here is the full mapping, the categories ETSI is not covering, and why none of it changes your Article 32 route yet.

By The CVD Portal Team
Supply Chain Security2026-07-29· 11 min read

The 2026 SBOM minimum elements: what changed, and where it collides with the CRA

CISA and seventeen partner agencies, seven of them EU national authorities, have replaced the 2021 NTIA SBOM minimum elements. The field count goes from seven to seventeen, Supplier Name becomes Component Producer, and Depth becomes Coverage with no minimum depth. That last change means a CRA-minimal SBOM fails the new baseline by construction. Here is the full delta, and why your SBOM can now pass one framework and fail another.

By The CVD Portal Team
CRA Compliance2026-07-22· 8 min read

What an empty risk assessment leaves out

A CRA risk assessment has to be the manufacturer's own determination, which is the strongest argument for starting from an empty document. The trouble is what an empty document selects for. Teams write down the threats they already discuss and leave out the interface nobody owns, the decommissioning path, and the failure that only appears at fleet scale. What a starting draft is for, and the one property it needs to stay safe.

By The CRA Portal Team
CRA Compliance2026-07-21· 7 min read

Your CRA technical file is mostly written already

Most manufacturers approaching the CRA technical file treat it as a writing project. It is a mapping project first. Annex VII asks you to demonstrate that specific evidence satisfies specific essential requirements, and the architecture diagrams, test reports and user documentation that demonstrate them usually already exist. Here is why the mapping is the hard part, and why a gap list computed before mapping measures the wrong thing.

By The CRA Portal Team
Technical Deep Dive2026-07-20· 7 min read

Your CRA evidence already lives in Jira: importing it instead of rewriting it

Annex VII asks for records of work that engineering teams already produce, in tickets and wiki pages. Most compliance tooling asks you to transcribe that record into a second set of documents, which then starts decaying immediately. CVD Portal now reads Jira and Confluence directly, so the technical file is built from the systems where the work actually happened.

By The CVD Portal Team
Technical Deep Dive2026-07-17· 9 min read

Running the CRA risk assessment in practice: CVD Portal and draft prEN 40000-1-2

Article 13 requires a documented cybersecurity risk assessment, and the draft European standard prEN 40000-1-2 describes the process a manufacturer should run to produce one. This post walks through how that process works in CVD Portal's products workspace, from product context and risk acceptance criteria to the Annex I applicability table, and maps every step to the regulation and to the draft standard's clauses.

By The CVD Portal Team

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.