Engineering Blog

CVD Portal Engineering

Technical insights on coordinated vulnerability disclosure, CRA compliance, and product security engineering.

CRA Compliance2026-07-2911 min read

The ETSI EN 304 Series: One CRA Standard Per Annex III Product Category

Everyone tracking CRA standardisation is watching the horizontal prEN 40000 series. The other half of standardisation request M/606 is 18 vertical standards, EN 304 617 to EN 304 642, one per Annex III product category, and ETSI has public drafts out for most of them. Here is the full mapping, the categories ETSI is not covering, and why none of it changes your Article 32 route yet.

By The CVD Portal Team
CRA Compliance2026-07-228 min read

What an Empty Risk Assessment Leaves Out

A CRA risk assessment has to be the manufacturer's own determination, which is the strongest argument for starting from an empty document. The trouble is what an empty document selects for. Teams write down the threats they already discuss and leave out the interface nobody owns, the decommissioning path, and the failure that only appears at fleet scale. What a starting draft is for, and the one property it needs to stay safe.

By The CRA Portal Team
CRA Compliance2026-07-217 min read

Your CRA Technical File Is Mostly Written Already

Most manufacturers approaching the CRA technical file treat it as a writing project. It is a mapping project first. Annex VII asks you to demonstrate that specific evidence satisfies specific essential requirements, and the architecture diagrams, test reports and user documentation that demonstrate them usually already exist. Here is why the mapping is the hard part, and why a gap list computed before mapping measures the wrong thing.

By The CRA Portal Team
Technical Deep Dive2026-07-207 min read

Your CRA Evidence Already Lives in Jira: Importing It Instead of Rewriting It

Annex VII asks for records of work that engineering teams already produce, in tickets and wiki pages. Most compliance tooling asks you to transcribe that record into a second set of documents, which then starts decaying immediately. CVD Portal now reads Jira and Confluence directly, so the technical file is built from the systems where the work actually happened.

By The CVD Portal Team
Technical Deep Dive2026-07-179 min read

Running the CRA Risk Assessment in Practice: CVD Portal and Draft prEN 40000-1-2

Article 13 requires a documented cybersecurity risk assessment, and the draft European standard prEN 40000-1-2 describes the process a manufacturer should run to produce one. This post walks through how that process works in CVD Portal's products workspace, from product context and risk acceptance criteria to the Annex I applicability table, and maps every step to the regulation and to the draft standard's clauses.

By The CVD Portal Team

CRA deadline briefing

A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.

We use your email only to send the briefing. Unsubscribe any time with one click.