Cyber Resilience Act
CRA guidance, official and practical
A single place to find CRA guidance. The official Commission and ENISA sources, the working guides for each compliance task, and tailored guidance for your role, industry, and country.
Official guidance
Start with the primary sources. The regulation text, the Commission's own guidance, and the ENISA infrastructure that underpins reporting.
The CRA regulation, article by article
Every article and annex of Regulation (EU) 2024/2847 explained in plain language.
European Commission draft guidance
What the Commission's draft guidance clarifies about scope and obligations.
ENISA, the EUVD and Article 14
The Single Reporting Platform, the European Vulnerability Database, and national CSIRTs.
Guidance by task
Working guides for the jobs a manufacturer actually has to do to comply.
How CRA compliance works
The end-to-end path from classification to CE marking.
CRA compliance checklist
A step-by-step checklist covering the core obligations.
CRA reporting obligations
The 24-hour and 72-hour reporting duties and who they apply to.
Article 14 reporting
Reporting actively exploited vulnerabilities and severe incidents.
Product classifier
Work out whether a product is default, important Class I or II, or critical.
Guidance by role, industry and country
Tailored guidance for who you are, what you build, and where you sell.
Standards guidance
How the CRA maps to the standards manufacturers use to demonstrate conformity.
Turn guidance into an audit-ready file
Work through the CRA obligations in one workspace and export an Annex VII technical file.
Get Started for Free