# CVD Portal > CVD Portal is a free, multi-tenant SaaS platform that gives EU manufacturers a whitelabel Coordinated Vulnerability Disclosure (CVD) portal and helps them comply with the EU Cyber Resilience Act (CRA, Regulation (EU) 2024/2847). From 11 September 2026, manufacturers of products with digital elements sold into the EU must receive vulnerability reports through a single point of contact and notify ENISA and national CSIRTs on fixed deadlines (Article 13 publication, Article 14 24-hour/72-hour/14-day reporting); the full regulation, including CE marking, applies from 11 December 2027. CVD Portal provides a branded HTTPS intake portal, 48-hour acknowledgment tracking, ENISA-aligned triage with CVSS scoring, and SRP-ready Article 14 filing packages prepared for manual submission. ## Core pages - [Homepage](https://cvdportal.com/): What CVD Portal is and the CRA deadline it addresses. - [How it works](https://cvdportal.com/how-it-works): Product walkthrough from portal setup to authority reporting. - [Features](https://cvdportal.com/features): Article 13/14 SLA tracking, branded SPOC portal, ENISA-aligned triage. - [Pricing](https://cvdportal.com/pricing): Free, Pro, and Enterprise plans (intake is free). - [For researchers](https://cvdportal.com/researchers): How security researchers submit vulnerability reports. - [Compare alternatives](https://cvdportal.com/compare): CVD Portal vs bug-bounty and VDP platforms for CRA use. - [About](https://cvdportal.com/about): Company background. - [Contact](https://cvdportal.com/contact): Get in touch. ## CRA compliance - [EU Cyber Resilience Act: the complete guide](https://cvdportal.com/cra/articles): What the CRA is, who is in scope, the 11 September 2026 and 11 December 2027 deadlines, every obligation, penalties, and all 40 articles and annexes explained. - [CRA hub](https://cvdportal.com/cra): Index of Cyber Resilience Act article explainers. - [CRA timeline countdown](https://cvdportal.com/countdown): Key dates table and live countdown to 11 September 2026. - [CRA checklist](https://cvdportal.com/cra-checklist): Step-by-step compliance checklist. - [CRA tracker](https://cvdportal.com/cra-tracker): Regulatory deadline tracker. - [CRA Exposure Study 2026](https://cvdportal.com/research/cra-exposure-2026): Original measured research. 145 EU manufacturers across four sectors scanned for RFC 9116 security.txt and a discoverable CVD policy; fewer than one in ten publish a valid security contact. Open methodology, CC BY 4.0 dataset, no company named. - [Article 14 compliance](https://cvdportal.com/cra-article-14-compliance): The 24h/72h/14-day reporting obligation. - [Coordinated Vulnerability Disclosure](https://cvdportal.com/coordinated-vulnerability-disclosure): CVD concepts and process. ## CRA FAQ - [Do I have to wait for the EN 40000 standards before I can comply with the CRA?](https://cvdportal.com/faq/do-i-have-to-wait-for-the-en-40000-standards): Waiting is the wrong plan. No part of the EN 40000 series has been cited in the Official Journal, so the Article 27 presumption of conformity is unavailable, and Article 32(2) escalates a Class I important product to third-party assessment precisely where a manufacturer has not applied a harmonised standard or where none exists. Compliance is owed from 11 December 2027 whatever the standards do. The series is drafted under Commission standardisation request M/606, with parts 1-1, 1-2 and 1-3 past public enquiry and awaiting approval. - [Do I have to report the same incident under the CRA, NIS2 and GDPR?](https://cvdportal.com/faq/do-i-report-the-same-incident-under-cra-nis2-and-gdpr): One event can trigger all three, and none of them excuses the others. CRA Article 14 binds the manufacturer when a vulnerability in its product is actively exploited or a severe incident affects product security, filed to a coordinating CSIRT and ENISA. NIS2 Article 23 binds essential and important entities when a significant incident disrupts their own services. GDPR Article 33 binds the controller within 72 hours of a personal data breach. The triggers, the subjects and the recipients differ, so the filings run in parallel. - [Does the EU Cyber Resilience Act apply to open source software?](https://cvdportal.com/faq/does-the-cra-apply-to-open-source-software): The Cyber Resilience Act (Regulation (EU) 2024/2847) covers free and open source software only where it is supplied for distribution or use in the course of a commercial activity. Software its manufacturer does not monetise stays outside the scope. A paid or enterprise edition is placed on the market and carries the full manufacturer obligations. Legal persons who sustain a project intended for commercial use fall under the lighter steward regime in Article 24, which carries no CE marking and no administrative fines. - [Does the CRA cover my web application?](https://cvdportal.com/faq/does-the-cra-cover-my-web-application): Generally no. Commission guidance confirms that software which executes remotely and is merely accessed by the user is not, on that basis alone, a product with digital elements. A web application reached exclusively through a browser therefore falls outside the CRA, as does a website that only presents information. Two things pull you back in. Shipping a client that users install and run locally is in scope, even where it is built with web technologies. And your backend enters scope where it supports a function of some other product. - [Is my software update a substantial modification under the CRA?](https://cvdportal.com/faq/is-my-software-update-a-substantial-modification): Ask four questions from Commission guidance point 110. Does the update introduce new threat vectors, enable new attack scenarios, change the likelihood of previously identified attack scenarios, or change their impact? Where all four are negative and the assumptions in your risk assessment still hold, the update is unlikely to be substantial. Any single yes makes it substantial, as does a change to the intended purpose the product was assessed against. The size of the change is irrelevant. - [Is there a CRA harmonised standard for my product category yet?](https://cvdportal.com/faq/is-there-a-cra-harmonised-standard-for-my-product-category): A draft or a work item exists for every Annex III category, and none of it is cited in the Official Journal, so the Article 27 presumption of conformity is unavailable for every product category without exception. Standardisation request M/606 splits into horizontal standards covering all products and vertical standards covering one category each. ETSI drafts most verticals as the EN 304 6xx series, where the number is 304 600 plus the mandate line item. CEN and CENELEC hold the semiconductor, smartcard, identity and metering categories. - [What do I actually have to do to comply with the Cyber Resilience Act?](https://cvdportal.com/faq/what-do-i-actually-have-to-do-to-comply-with-the-cra): Compliance runs as an ordered sequence where each step feeds the next. Confirm the product is in scope and that you are its manufacturer, then classify it as default, Annex III important class I or II, or Annex IV critical. Run the Article 13(2) risk assessment, which determines which Annex I Part I requirements apply. Build to those, meet the Part II vulnerability handling requirements, compile Article 31 technical documentation, complete the Article 32 conformity assessment, draw up the EU declaration of conformity, affix the CE marking, and report under Article 14. - [What documents and reports does the Cyber Resilience Act require me to produce?](https://cvdportal.com/faq/what-documents-does-the-cra-require-me-to-produce): The Cyber Resilience Act requires six artefacts. Technical documentation under Article 31 and Annex VII, which contains the risk assessment. An EU declaration of conformity under Article 28 and Annex V. A software bill of materials and a coordinated vulnerability disclosure policy, both under Annex I Part II. Information and instructions to the user under Annex II. Then the Article 14 filings once reporting begins. Technical documentation and the declaration are kept available to market surveillance authorities for at least 10 years or the support period, whichever is longer. - [What does the Cyber Resilience Act require in a cybersecurity risk assessment?](https://cvdportal.com/faq/what-does-the-cra-require-in-a-risk-assessment): Article 13(2) of the Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers to assess the cybersecurity risks of a product with digital elements and to carry the outcome through the planning, design, development, production, delivery and maintenance phases. Article 13(3) requires that assessment to be documented, kept updated across the support period, and to state which Annex I Part I point 2 requirements apply and how they are met. It forms part of the technical documentation under Article 31 and Annex VII, and the duty applies from 11 December 2027. - [When does the CRA reporting clock start?](https://cvdportal.com/faq/when-does-the-cra-reporting-clock-start): The clock starts when you become aware, and Commission guidance now defines that moment. On detecting a suspicious event or receiving a report from a researcher, customer or authority, assess it immediately. You become aware once that initial assessment gives you a reasonable degree of certainty that a vulnerability in your product is being actively exploited, or that a severe incident has compromised your product's security. Receiving a report does not by itself start the clock, and neither does a vague suspicion you have not yet examined. - [Which CSIRT do I report to under the CRA, and how does the ENISA single reporting platform work?](https://cvdportal.com/faq/which-csirt-do-i-report-to-under-the-cra): Article 14(7) of the Cyber Resilience Act routes every notification to the CSIRT designated as coordinator in the Member State where the manufacturer has its main establishment in the Union, meaning where decisions about the cybersecurity of its products are predominantly taken. A manufacturer with no establishment in the Union follows a four-step fallback based on authorised representative, importer, distributor, then users. One submission through the ENISA single reporting platform reaches that CSIRT and ENISA simultaneously, and the deadlines run from 11 September 2026. ## Commission guidance worked examples (C(2026) 5252, verbatim) - [How does core functionality decide a product's CRA classification?](https://cvdportal.com/cra-guidance/examples/core-functionality-and-product-classification): Classification follows core functionality, judged against the technical descriptions in Implementing Regulation (EU) 2025/2392. A product that merely integrates an operating system does not take on the core functionality of one. SOAR software generally exceeds the SIEM category and log viewers fall short of it. Modules offered on separate subscriptions are separate products, each classified on its own. Extra functions do not push a product into a stricter conformity route, and the presumption of conformity covers only what the harmonised standard covers. - [How does the CRA cybersecurity risk assessment justify design decisions?](https://cvdportal.com/cra-guidance/examples/cra-risk-assessment-worked-examples): The Commission's risk assessment examples all turn on the same move. The Article 13(2) assessment decides what a product needs, and it can justify choices that look like gaps. Supporting a legacy protocol for interoperability, integrating a component bought before the CRA applied, placing an older design on the market without redesign, limiting a sensor's intended purpose instead of hardening it, and relying on the operating system's cryptography rather than writing your own are each defensible where the assessment carries them. - [How long must a CRA support period be, and does a substantial modification extend it?](https://cvdportal.com/cra-guidance/examples/how-long-must-my-support-period-be): Article 13(8) sets the support period by reference to the time the product is expected to be in use. The five year figure is a safeguard floor rather than a default, and products expected to last longer need correspondingly longer periods. Article 13(10) lets a manufacturer remediate only the version last placed on the market, provided users can upgrade free of charge and without additional costs. A substantial modification triggers a reassessment but does not automatically reset or extend the period. - [Is my cloud back end a remote data processing solution under the CRA?](https://cvdportal.com/cra-guidance/examples/is-my-backend-a-remote-data-processing-solution): Remote data processing is part of your product when two things hold together. The product cannot perform one of its functions without it, and the software was designed and developed by you or under your responsibility. Your own back end qualifies even when it runs on third-party infrastructure. A general purpose third-party SaaS does not, and is treated as a component instead. Systems your product never talks to directly fall outside, and a cellular network is neither a solution nor a component. - [Are spare parts and repairs subject to the Cyber Resilience Act?](https://cvdportal.com/cra-guidance/examples/repairs-and-spare-parts-under-the-cra): Article 2(6) takes spare parts outside the CRA where they replace identical components in a product with digital elements. The Commission's examples turn on what identical means. A replacement module built to the same specifications is exempt, whether the host product predates the CRA or not. A newer chip with a different cryptographic implementation and secure boot mechanism is not identical and is a product in its own right. A different chipset can still be identical where the protocols and security mechanisms are unchanged. - [Which software updates has the Commission called substantial modifications?](https://cvdportal.com/cra-guidance/examples/substantial-modification-worked-examples): The Commission tests a software update by its effect on the cybersecurity risk profile rather than by its size. A persistent login feature storing authentication tokens locally is a substantial modification. So is a diagnostics export that leaves sensitive operational data unencrypted. Enabling control features that shipped disabled but assessed is not, and neither is group messaging the original assessment anticipated. Security updates generally fall outside, until they change the intended purpose or add new external dependencies. - [What counts as a product with digital elements under the Cyber Resilience Act?](https://cvdportal.com/cra-guidance/examples/what-counts-as-a-product-with-digital-elements): The Cyber Resilience Act reaches software that is supplied to a user and executes on that user's device. A mobile application, a desktop application built with web technologies, and source code licensed in a text file are all products with digital elements. A web application used only through a browser is not, unless it supports the functionality of a product that is. Hardware and software that cannot deliver their purpose without each other form one product, even when they are supplied through different channels. - [When is open source software supplied in the course of a commercial activity?](https://cvdportal.com/cra-guidance/examples/when-open-source-falls-under-the-cra): The Cyber Resilience Act reaches free and open-source software only where it is supplied in the course of a commercial activity. The Commission's twenty-two examples locate that line. Charging for a paid version, gating releases or security fixes behind donations, monetising what is sold through the software, and requiring unrelated personal data processing all cross it. Voluntary donations, separately sold consultancy, funded features released openly, and contributing to someone else's project do not. ## CRA article explainers - [Essential Cybersecurity Requirements for Products with Digital Elements](https://cvdportal.com/cra/annex-i): The full list of CRA Annex I essential cybersecurity requirements every product with digital elements must meet, across secure design, development, and vulnerability handling. - [Information and Instructions to Users Required Under the CRA](https://cvdportal.com/cra/annex-ii): CRA Annex II specifies the mandatory information manufacturers must provide to users, including CVD contact details, support period, CE marking reference, and security update information. - [Important Products with Digital Elements - Class I and Class II Classification](https://cvdportal.com/cra/annex-iii): The full CRA Annex III list of Important Products in Class I and Class II, which ones need third-party conformity assessment, and what each class means for CE marking. - [Critical Products with Digital Elements - Highest-Risk Classification](https://cvdportal.com/cra/annex-iv): The CRA Annex IV list of Critical Products, the three categories it covers, and the strictest CRA conformity route under Article 32(4). - [EU Declaration of Conformity: Required Fields and Structure](https://cvdportal.com/cra/annex-v): CRA Annex V specifies the model structure of the EU Declaration of Conformity: product identification, manufacturer details, the sole-responsibility statement, standards applied, notified body details and signature. - [Simplified EU Declaration of Conformity: Model Structure](https://cvdportal.com/cra/annex-vi): CRA Annex VI sets the model structure for the simplified EU Declaration of Conformity: a short conformity statement plus the internet address where the full Annex V declaration is available. - [Technical Documentation Requirements Under the CRA](https://cvdportal.com/cra/annex-vii): CRA Annex VII specifies the required contents of the technical file: product description, design docs, risk assessment, SBOM, test results, and CVD policy reference. - [Conformity Assessment Procedures: Modules A, B, C and H](https://cvdportal.com/cra/annex-viii): CRA Annex VIII sets out the conformity assessment procedures: internal control (Module A), EU type-examination (Module B), conformity to type (Module C) and full quality assurance (Module H). - [Subject Matter and Purpose of the Cyber Resilience Act](https://cvdportal.com/cra/article-1): CRA Article 1 defines the subject matter of the EU Cyber Resilience Act: mandatory cybersecurity requirements for all products with digital elements placed on the EU market. - [Obligations of Manufacturers](https://cvdportal.com/cra/article-13): CRA Article 13 sets the core manufacturer duties under the Cyber Resilience Act, covering security by design, risk assessment, SBOM, security updates, and coordinated vulnerability disclosure. - [Active Exploitation and Incident Reporting - 24h, 72h, and 14-Day Obligations](https://cvdportal.com/cra/article-14): CRA Article 14 explained. The 24-hour early warning, 72-hour notification, and 14-day final report deadlines to ENISA and your CSIRT, in force from September 2026. - [Voluntary Reporting of Vulnerabilities and Incidents](https://cvdportal.com/cra/article-15): CRA Article 15 allows manufacturers and other parties to voluntarily notify national CSIRTs and ENISA of vulnerabilities and incidents that do not trigger Article 14 mandatory reporting, supporting proactive intelligence sharing. - [Establishment of the Single Reporting Platform and ENISA's Vulnerability Coordination Role](https://cvdportal.com/cra/article-16): CRA Article 16 establishes ENISA's single reporting platform for Article 14 notifications, the European Vulnerability Database (EVDB), and ENISA's coordination role in EU-wide vulnerability disclosure. - [Other Provisions Related to Reporting](https://cvdportal.com/cra/article-17): CRA Article 17 covers what happens around your Article 14 and 15 notifications: EU-CyCLONe sharing, CSIRT public disclosure powers, the no-increased-liability shield, EU vulnerability database entries, and CSIRT helpdesk support for SMEs. - [Authorised Representatives: EU Presence for Non-EU Manufacturers](https://cvdportal.com/cra/article-18): CRA Article 18 requires non-EU manufacturers selling products in the EU to appoint an EU-based authorised representative who can act on their behalf for CRA compliance purposes. - [Importer Obligations Under the Cyber Resilience Act](https://cvdportal.com/cra/article-19): CRA Article 19 sets out the due diligence and verification obligations of importers who place non-EU-manufactured products with digital elements on the EU market. - [Scope and Exclusions Under the Cyber Resilience Act](https://cvdportal.com/cra/article-2): CRA Article 2 defines which products fall within scope and lists key exclusions: medical devices, aviation, vehicles, military, and national security products. - [Distributor Obligations Under the Cyber Resilience Act](https://cvdportal.com/cra/article-20): CRA Article 20 defines the due diligence obligations of distributors who make products with digital elements available in the EU market without being the original importer. - [When Importers and Distributors Are Treated as Manufacturers](https://cvdportal.com/cra/article-21): CRA Article 21 explains when importers or distributors who modify products or sell under their own brand take on full manufacturer obligations under the Cyber Resilience Act. - [Identification and Obligations of Economic Operators](https://cvdportal.com/cra/article-23): CRA Article 23 sets out when and how manufacturers must report incidents and vulnerabilities to market surveillance authorities and ENISA beyond Article 14. - [Obligations of Open-Source Software Stewards Under the CRA](https://cvdportal.com/cra/article-24): CRA Article 24 defines 'open-source software stewards' and sets out their specific obligations — lighter than full manufacturer duties but requiring a security policy, CVD process, and cooperation with market surveillance authorities. - [Security Attestation of Free and Open-Source Software](https://cvdportal.com/cra/article-25): CRA Article 25 establishes a voluntary EU security attestation programme for free and open-source software components, run by ENISA, to help manufacturers meet their component due diligence obligations under Article 13. - [Presumption of Conformity, Harmonised Standards, and Common Specifications](https://cvdportal.com/cra/article-27): CRA Article 27 establishes the presumption of conformity for products that apply EU harmonised standards or common specifications, and covers formal objection procedures for inadequate standards. - [EU Declaration of Conformity: Content, Structure, and Requirements](https://cvdportal.com/cra/article-28): CRA Article 28 specifies the required content of the EU Declaration of Conformity that manufacturers must draw up before affixing the CE marking to products with digital elements. - [Definitions: Key Terms in the Cyber Resilience Act](https://cvdportal.com/cra/article-3): CRA Article 3 sets out the statutory definitions for the Cyber Resilience Act, including 'product with digital elements', 'manufacturer', 'importer', 'distributor', and related terms that determine who the regulation applies to and what it covers. - [Rules and Conditions for Affixing the CE Marking](https://cvdportal.com/cra/article-30): CRA Article 30 sets the technical rules for affixing the CE marking to products with digital elements: where, when, how, and what the marking must include — including the notified body identification number for Module H assessments. - [Conformity Assessment Procedures: Module A vs Third-Party Assessment](https://cvdportal.com/cra/article-32): CRA Article 32 explains when manufacturers can self-certify (Module A) versus when third-party notified body assessment is required for Class I and Class II products. - [Support Measures for Microenterprises and SMEs](https://cvdportal.com/cra/article-33): CRA Article 33 obliges member states and the Commission to support small manufacturers with awareness raising, training, simplified documentation, sandboxes, and dedicated channels. What SMEs can actually claim. - [Notification of Conformity Assessment Bodies to the European Commission](https://cvdportal.com/cra/article-35): CRA Article 35 governs how member states notify conformity assessment bodies (notified bodies) to the European Commission for the purpose of CRA third-party assessments. - [Notification of Conformity Assessment Bodies](https://cvdportal.com/cra/article-39): CRA Article 39 establishes the requirements member states must meet before notifying a conformity assessment body to the European Commission for CRA third-party assessment purposes. - [Free Movement of CRA-Compliant Products in the EU Single Market](https://cvdportal.com/cra/article-4): CRA Article 4 grants CE-marked products with digital elements the right to free movement across the EU single market, provided they meet essential cybersecurity requirements. - [Procurement and Professional Use of Products with Digital Elements](https://cvdportal.com/cra/article-5): CRA Article 5 addresses cybersecurity obligations for organisations that procure or professionally use products with digital elements, including public sector bodies and critical infrastructure operators. - [Market Surveillance Coordination Between EU Member States](https://cvdportal.com/cra/article-52): CRA Article 52 establishes coordination mechanisms between national market surveillance authorities to ensure consistent CRA enforcement across the EU single market. - [Joint Activities of Market Surveillance Authorities](https://cvdportal.com/cra/article-59): CRA Article 59 empowers national market surveillance authorities to conduct joint investigations and coordinated enforcement actions against manufacturers suspected of CRA non-compliance, particularly where cybersecurity risks have cross-border implications. - [Essential Cybersecurity Requirements for Products with Digital Elements](https://cvdportal.com/cra/article-6): CRA Article 6 requires products with digital elements to meet the essential security requirements in Annex I, covering both security properties and vulnerability handling obligations. - [Administrative Fines for CRA Non-Compliance](https://cvdportal.com/cra/article-64): CRA Article 64 establishes a three-tier administrative fine regime: up to €15M or 2.5% of global turnover for essential requirements violations, €10M or 2% for other obligations, and €5M or 1% for misleading authorities. - [Important Products with Digital Elements - Annex III Classification](https://cvdportal.com/cra/article-7): CRA Article 7 defines 'important products with digital elements' under Annex III — two classes of higher-risk products subject to stricter conformity assessment requirements, including mandatory third-party involvement for Class II. - [Critical Products with Digital Elements - Annex IV Classification](https://cvdportal.com/cra/article-8): CRA Article 8 defines 'critical products with digital elements' listed in Annex IV — the highest-risk product category requiring mandatory third-party conformity assessment via an EU cybersecurity certification scheme. ## Industry guides - [Access Control & Physical Security Vendors](https://cvdportal.com/guides/access-control-systems): EU Cyber Resilience Act compliance guide for access control and physical security vendors. Covers Class I classification, Annex I security requirements, Article 13 CVD obligations, Article 14 incident reporting, and conformity assessment for electronic access and security products. - [Agricultural IoT & Precision Farming Vendors](https://cvdportal.com/guides/agricultural-iot): EU Cyber Resilience Act compliance guide for agricultural IoT and precision farming vendors. Covers product classification for farm sensors and controllers, Annex I obligations, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment. - [Professional Audio-Visual Equipment Vendors](https://cvdportal.com/guides/audio-visual-equipment): EU Cyber Resilience Act compliance guide for professional audio-visual equipment vendors. Covers CRA classification for AV hardware, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for professional AV products. - [Automotive OEMs & Tier-1 Suppliers](https://cvdportal.com/guides/automotive-oems): EU Cyber Resilience Act compliance guide for automotive OEMs and Tier-1 suppliers. Covers product classification, Article 13 CVD obligations, Article 14 incident reporting, and conformity assessment pathways for connected vehicle components. - [Avionics & Aerospace Systems Manufacturers](https://cvdportal.com/guides/avionics-manufacturers): EU CRA obligations for avionics manufacturers: scope, safety-critical product classification, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment pathways. - [Chemical & Process Plant Automation Vendors](https://cvdportal.com/guides/chemical-plant-automation): EU CRA obligations for chemical process automation vendors: Seveso interaction, Class II classification, Article 13 CVD requirements, Article 14 incident reporting, and conformity assessment. - [Connected Vehicle Platform & V2X Vendors](https://cvdportal.com/guides/connected-vehicle-platforms): EU CRA obligations for connected vehicle platform and V2X vendors: automotive product scope, Article 13 CVD requirements, Article 14 incident reporting, and UNECE WP.29 interaction. - [Consumer Electronics Brands](https://cvdportal.com/guides/consumer-electronics-brands): EU Cyber Resilience Act compliance guide for consumer electronics brands. Covers product classification, Annex I security requirements, Article 13 CVD policy obligations, Article 14 incident reporting, and conformity assessment for connected consumer products. - [Cybersecurity Product Vendors](https://cvdportal.com/guides/cybersecurity-product-vendors): EU Cyber Resilience Act compliance guide for cybersecurity product vendors. Covers Class I and Class II classification for security tools, Annex I obligations, Article 13 CVD policy requirements, Article 14 incident reporting, and conformity assessment. - [Digital Signage & Kiosk Vendors](https://cvdportal.com/guides/digital-signage-vendors): EU Cyber Resilience Act compliance guide for digital signage and kiosk vendors. Covers product classification, Annex I security requirements for signage hardware, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for interactive kiosks. - [Drone & UAV Manufacturers](https://cvdportal.com/guides/drone-uav-manufacturers): EU Cyber Resilience Act compliance guide for drone and UAV manufacturers. Covers product classification, Annex I security requirements for UAS, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for commercial and consumer drone products. - [Electronic Health Record & Clinical IT Vendors](https://cvdportal.com/guides/electronic-health-records): EU CRA obligations for EHR and clinical IT vendors: EHDS interaction, Important Product classification, Article 13 CVD requirements, Article 14 incident reporting, and CE marking pathways. - [Electronic Lock & Smart Door Manufacturers](https://cvdportal.com/guides/electronic-locks-vendors): EU CRA obligations for electronic lock and smart door manufacturers: product classification, Annex I security requirements, Article 13 CVD policy, and CE marking pathways. - [Energy Management System Vendors](https://cvdportal.com/guides/energy-management-systems): EU Cyber Resilience Act compliance guide for energy management system vendors. Covers Critical Class II classification, Annex I security obligations, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for energy sector software and hardware. - [Enterprise Networking Equipment Vendors](https://cvdportal.com/guides/enterprise-networking-vendors): EU Cyber Resilience Act compliance guide for enterprise networking equipment vendors. Covers Class I classification for switches and routers, Annex I obligations, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment pathways. - [EV Charging & EVSE Manufacturers](https://cvdportal.com/guides/ev-charging-manufacturers): EU Cyber Resilience Act compliance for EV chargers and EVSE manufacturers. Compliance for EV chargers covering product classification, OCPP and ISO 15118 security under Annex I, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment. How AFIR and the CRA fit together. - [Facilities Management & CAFM System Vendors](https://cvdportal.com/guides/facilities-management-systems): EU CRA obligations for CAFM and facilities management system vendors: product scope, Article 13 CVD requirements, Article 14 incident reporting, and conformity assessment pathways. - [Firewall & Network Security Appliance Manufacturers](https://cvdportal.com/guides/firewall-manufacturers): EU CRA obligations for firewall and network security appliance manufacturers: Class II classification, Article 13 CVD policy, Article 14 reporting, and notified body assessment requirements. - [Fleet Management & Telematics Vendors](https://cvdportal.com/guides/fleet-management-vendors): EU Cyber Resilience Act compliance guide for fleet management and telematics vendors. Covers product classification for OBD and telematics hardware, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment. - [Food & Beverage Automation System Vendors](https://cvdportal.com/guides/food-beverage-automation): EU CRA obligations for food and beverage automation vendors: product classification, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and CE marking. - [Gaming Hardware Manufacturers](https://cvdportal.com/guides/gaming-hardware-manufacturers): EU Cyber Resilience Act compliance guide for gaming hardware manufacturers. Covers product classification for consoles and peripherals, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for gaming products. - [Healthcare IT & Clinical Software Vendors](https://cvdportal.com/guides/healthcare-it-providers): EU Cyber Resilience Act compliance guide for healthcare IT and clinical software vendors. Covers product classification for clinical software, Annex I obligations, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for health information systems. - [Home Health Monitoring Device Manufacturers](https://cvdportal.com/guides/home-health-monitoring): EU CRA obligations for home health monitoring device manufacturers: MDR interaction, Article 13 CVD requirements, Article 14 reporting, consumer device security, and CE marking. - [HVAC & Climate Control Manufacturers](https://cvdportal.com/guides/hvac-manufacturers): EU Cyber Resilience Act compliance guide for HVAC and climate control manufacturers. Covers product classification for connected HVAC systems, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment. - [Industrial Automation & PLC Vendors](https://cvdportal.com/guides/industrial-automation-vendors): EU Cyber Resilience Act compliance guide for industrial automation and PLC vendors. Covers OT product classification, Annex I security requirements, Article 13 CVD policy obligations, Article 14 incident reporting, and conformity assessment for ICS products. - [Connected Laboratory Instrument Manufacturers](https://cvdportal.com/guides/laboratory-instruments): EU CRA obligations for connected laboratory instrument manufacturers: product scope, security-by-design, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment. - [Livestock Monitoring & Precision Livestock Farming](https://cvdportal.com/guides/livestock-monitoring): EU CRA obligations for livestock monitoring and precision livestock farming vendors: IoT device scope, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment pathways. - [Managed Service Providers with On-Premises Software](https://cvdportal.com/guides/managed-service-providers): EU CRA obligations for managed service providers distributing on-premises software: product scope, Article 13 CVD requirements, Article 14 incident reporting, and CE marking guidance. - [Maritime Navigation & Vessel Systems Vendors](https://cvdportal.com/guides/maritime-navigation-systems): EU Cyber Resilience Act obligations for maritime navigation and vessel system vendors: product scope, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment pathways. - [Medical Device Manufacturers](https://cvdportal.com/guides/medical-device-manufacturers): EU Cyber Resilience Act compliance guide for medical device manufacturers. Covers MDR/CRA overlap, Class I classification, Article 13 CVD obligations, Article 14 incident reporting, and conformity assessment for connected medical devices. - [Oil & Gas Automation Vendors](https://cvdportal.com/guides/oil-gas-automation): EU Cyber Resilience Act obligations for oil and gas automation vendors: scope, Article 13 CVD requirements, Article 14 incident reporting, and conformity assessment pathways. - [Parking Management & Smart Parking Vendors](https://cvdportal.com/guides/parking-management-systems): EU Cyber Resilience Act obligations for smart parking and parking management system vendors: classification, CVD policy, Article 14 incident reporting, and CE marking requirements. - [Pharmaceutical Manufacturing Automation Vendors](https://cvdportal.com/guides/pharmaceutical-manufacturing): EU CRA obligations for pharmaceutical automation vendors: GMP interaction, product classification, Article 13 CVD requirements, Article 14 incident reporting, and conformity assessment. - [Point-of-Care Diagnostics & IVD Manufacturers](https://cvdportal.com/guides/point-of-care-diagnostics): EU CRA requirements for point-of-care diagnostics and IVD manufacturers: IVDR interaction, CRA classification, CVD policy under Article 13, incident reporting, and conformity assessment. - [Port & Logistics Automation System Vendors](https://cvdportal.com/guides/port-automation-systems): EU CRA obligations for port and logistics automation vendors: critical infrastructure classification, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment. - [Point-of-Sale & Payment Terminal Vendors](https://cvdportal.com/guides/pos-system-vendors): EU Cyber Resilience Act compliance guide for point-of-sale and payment terminal vendors. Covers Class I classification, Annex I security requirements, PCI DSS alignment, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for payment products. - [Precision Agriculture & AgTech Vendors](https://cvdportal.com/guides/precision-agriculture): EU Cyber Resilience Act compliance guide for precision agriculture and AgTech vendors. Covers CRA classification for farm automation hardware, Annex I security obligations, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for agricultural technology. - [Private 5G & Industrial Wireless Vendors](https://cvdportal.com/guides/private-5g-vendors): EU CRA obligations for private 5G and industrial wireless vendors: network equipment classification, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment requirements. - [Railway Signalling & Train Control Vendors](https://cvdportal.com/guides/railway-signalling-systems): EU CRA obligations for railway signalling and train control vendors: safety-critical classification, Article 13 CVD requirements, Article 14 incident reporting, and conformity assessment. - [Robotics & Collaborative Robot Manufacturers](https://cvdportal.com/guides/robotics-manufacturers): EU Cyber Resilience Act compliance guide for robotics and collaborative robot manufacturers. Covers product classification, Annex I security obligations, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for industrial and collaborative robots. - [Smart Appliance Manufacturers](https://cvdportal.com/guides/smart-appliance-manufacturers): EU Cyber Resilience Act compliance guide for smart appliance manufacturers. Covers product classification for connected white goods, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for smart home appliances. - [Smart City Infrastructure Vendors](https://cvdportal.com/guides/smart-city-infrastructure): EU CRA obligations for smart city infrastructure vendors: product classification, Article 13 CVD requirements, Article 14 incident reporting, public sector procurement, and CE marking. - [Smart Home Device Manufacturers](https://cvdportal.com/guides/smart-home-manufacturers): EU Cyber Resilience Act compliance guide for smart home device manufacturers. Covers product classification for IoT devices, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for connected home products. - [Smart Meter & AMI Manufacturers](https://cvdportal.com/guides/smart-meter-manufacturers): EU Cyber Resilience Act compliance guide for smart meter and AMI manufacturers. Covers Class I classification, Annex I security obligations for metering hardware, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for smart metering products. - [Smart Traffic Management System Vendors](https://cvdportal.com/guides/smart-traffic-management): EU CRA obligations for smart traffic management vendors: Important Product classification, Article 13 CVD requirements, Article 14 incident reporting, and conformity assessment guidance. - [Solar & Renewable Energy Monitoring Vendors](https://cvdportal.com/guides/solar-monitoring-vendors): CRA obligations for solar and renewable energy monitoring vendors: product classification, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment requirements. - [Telecom Equipment Vendors](https://cvdportal.com/guides/telecom-equipment-vendors): EU Cyber Resilience Act compliance guide for telecom equipment vendors. Covers Class I and Class II classification for network hardware, Annex I security obligations, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for telecom products. - [Telemedicine & Remote Patient Monitoring Vendors](https://cvdportal.com/guides/telemedicine-devices): EU CRA obligations for telemedicine and remote patient monitoring vendors: dual MDR/CRA compliance, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment. - [Video Surveillance & CCTV Vendors](https://cvdportal.com/guides/video-surveillance-vendors): EU Cyber Resilience Act compliance guide for video surveillance and CCTV vendors. Covers Class I classification for IP cameras, Annex I security requirements, Article 13 CVD policy, Article 14 incident reporting, and conformity assessment for surveillance products. - [Water Treatment & Utilities Automation Vendors](https://cvdportal.com/guides/water-treatment-automation): EU CRA obligations for water treatment automation vendors: critical infrastructure classification, CVD requirements under Article 13, Article 14 reporting, and conformity assessment pathways. - [Wearable Technology Brands](https://cvdportal.com/guides/wearable-tech-brands): EU Cyber Resilience Act compliance for wearable and smartwatch brands. Product classification, Annex I security requirements, Article 13 CVD policy, and Article 14 reporting for fitness trackers. ## Compliance checklists - [Access Control & Physical Security Systems](https://cvdportal.com/compliance/access-control): CRA compliance for access control and physical security system manufacturers. Electronic locks, card readers, biometric systems and IP-connected security hardware requirements. - [Assistive Technologies & AAC Devices](https://cvdportal.com/compliance/assistive-devices): CRA compliance for assistive technology and AAC device manufacturers. Covers non-MDR assistive devices, augmentative communication systems, and connected accessibility equipment. - [Professional Audio/Video Equipment](https://cvdportal.com/compliance/audio-video-pro): CRA compliance for professional audio and video equipment manufacturers. Networked broadcast systems, IP audio, live production equipment, and AV-over-IP under the Cyber Resilience Act. - [Automotive Electronics & In-Vehicle Systems](https://cvdportal.com/compliance/automotive-electronics): CRA compliance for automotive electronics manufacturers. UN R155/R156 and CRA intersection, ECU security, OTA updates, and in-vehicle cybersecurity requirements explained. - [Building Automation & Smart Buildings](https://cvdportal.com/compliance/building-automation): CRA compliance for building automation, HVAC controllers, BMS, and smart building systems. Annex III classification, Article 14 reporting, BACnet/Modbus security, and CVD obligations. - [CCTV & Video Surveillance](https://cvdportal.com/compliance/cctv-surveillance): CRA compliance for CCTV and video surveillance manufacturers. Covers IP cameras, NVR/DVR systems, VMS software, and biometric surveillance under the Cyber Resilience Act. - [CNC Machines & Industrial 3D Printers](https://cvdportal.com/compliance/cnc-3d-printing): CRA compliance for CNC machine and industrial 3D printer manufacturers. Annex I security requirements, SBOM, CVD policy, and CE marking under the Cyber Resilience Act. - [Consumer Routers & Modems](https://cvdportal.com/compliance/consumer-routers): CRA compliance checklist for consumer router and modem manufacturers. Article 13 CVD policy, Article 14 reporting, Annex I security requirements, and CE marking. - [Dental Equipment & Devices](https://cvdportal.com/compliance/dental-devices): CRA compliance for dental equipment manufacturers. Understand when dental devices fall under MDR exclusion vs full CRA scope. Covers digital imaging, practice management software. - [Digital Signage & Display Systems](https://cvdportal.com/compliance/digital-signage): CRA compliance for digital signage and display system manufacturers. Connected displays, media players, signage management platforms, and interactive display requirements. - [Drones & Unmanned Aerial Vehicles](https://cvdportal.com/compliance/drone-uav): CRA compliance for drone and UAV manufacturers. Annex III Class II likely for higher-category drones. Interaction with EU Drone Regulation (2019/947) and UAS category requirements. - [E-Readers & Consumer Tablets](https://cvdportal.com/compliance/e-readers-tablets): CRA compliance checklist for e-reader and consumer tablet manufacturers. Article 13 CVD policy, Annex I security requirements, firmware updates, and CE marking obligations. - [Edge Computing Devices & Gateways](https://cvdportal.com/compliance/edge-computing): CRA compliance for edge computing device and gateway manufacturers. Industrial IoT gateways, edge AI appliances, and fog computing nodes under the Cyber Resilience Act. - [Embedded Linux Devices](https://cvdportal.com/compliance/embedded-linux-devices): CRA compliance for embedded Linux device manufacturers. SBOM for open-source components, kernel security, CVD policy, and firmware update requirements under the Cyber Resilience Act. - [Energy Management Systems](https://cvdportal.com/compliance/energy-management): CRA compliance checklist for energy management system manufacturers. Annex III Class II requirements for critical infrastructure energy systems under the Cyber Resilience Act. - [Enterprise Networking Equipment](https://cvdportal.com/compliance/enterprise-networking): CRA compliance for enterprise switches, firewalls, and networking equipment. Annex III classification, CVD obligations, Article 14 reporting, and conformity assessment. - [Environmental Monitoring Sensors](https://cvdportal.com/compliance/environmental-monitoring): CRA compliance for environmental monitoring sensor manufacturers. Air quality, water quality, weather, and soil sensors under the Cyber Resilience Act requirements. - [EV Charging Equipment](https://cvdportal.com/compliance/ev-charging): CRA compliance for EV charger manufacturers. Annex III classification for public charging networks, Article 14 reporting, OCPP security, CVD obligations, and CE marking. - [Fire Safety & Detection Systems](https://cvdportal.com/compliance/fire-safety-systems): CRA compliance for fire safety and detection system manufacturers. Annex III Class II for networked fire safety systems. Covers fire alarms, suppression controllers, and life safety systems. - [Fleet Management & Telematics](https://cvdportal.com/compliance/fleet-management): CRA compliance for fleet management and telematics manufacturers. Covers OBD trackers, tachographs, ELD devices, and connected fleet management platforms. - [Gaming Consoles & Peripherals](https://cvdportal.com/compliance/gaming-devices): CRA compliance checklist for gaming console and peripheral manufacturers. Covers firmware security, online services, vulnerability disclosure and CE marking requirements. - [Health Monitoring Wearables](https://cvdportal.com/compliance/health-wearables): CRA compliance for health wearable manufacturers. Non-MDR health devices fall under full CRA scope. Covers firmware security, health data protection, CVD policy and CE marking. - [Hospital IT & Clinical Information Systems](https://cvdportal.com/compliance/hospital-systems): CRA compliance for hospital IT and clinical information system manufacturers. Non-MDR healthcare software falls under full CRA scope - checklist covering all key obligations. - [Hotel & Hospitality Systems](https://cvdportal.com/compliance/hotel-systems): CRA compliance for hotel and hospitality technology manufacturers. Smart locks, in-room controls, property management systems, and guest Wi-Fi under the Cyber Resilience Act. - [Industrial Controllers & PLCs](https://cvdportal.com/compliance/industrial-controllers): CRA compliance checklist for industrial controller and PLC manufacturers. Covers Article 13 CVD obligations, Article 14 reporting, Annex I requirements, and conformity assessment. - [Industrial Robotics & Collaborative Robots](https://cvdportal.com/compliance/industrial-robotics): CRA compliance for industrial robot and cobot manufacturers. Annex I security requirements, safety-security intersection, CVD policy, and CE marking under the Cyber Resilience Act. - [Intruder Alarm & Security Systems](https://cvdportal.com/compliance/intruder-alarm): CRA compliance for intruder alarm and security system manufacturers. Annex III Class II for critical facility protection. Covers alarm panels, PIR sensors, and monitoring system requirements. - [IoT Sensors & Connected Devices](https://cvdportal.com/compliance/iot-sensors): CRA compliance checklist for IoT sensor and connected device manufacturers. Article 13 CVD obligations, Annex I security requirements, firmware update obligations. - [Laboratory Instruments & Scientific Equipment](https://cvdportal.com/compliance/laboratory-instruments): CRA compliance for laboratory instrument and scientific equipment manufacturers. Networked analysers, laboratory information systems, and connected scientific instruments under the CRA. - [Livestock Monitoring Systems](https://cvdportal.com/compliance/livestock-monitoring): CRA compliance for livestock monitoring system manufacturers. Connected ear tags, health sensors, automated feeding systems, and farm analytics platforms under the Cyber Resilience Act. - [Marine Electronics & Navigation Systems](https://cvdportal.com/compliance/marine-electronics): CRA compliance for marine electronics and navigation system manufacturers. Covers AIS, ECDIS, chartplotters, VHF radio, and connected marine systems under the Cyber Resilience Act. - [Medical Devices](https://cvdportal.com/compliance/medical-devices): Medical device manufacturers: understand the overlap between CRA and MDR cybersecurity requirements. Checklist of where MDR satisfies CRA and where additional steps are needed. - [Network Attached Storage (NAS)](https://cvdportal.com/compliance/network-attached-storage): CRA compliance checklist for NAS manufacturers. Covers firmware security, ransomware resilience, CVD policy, remote access security, and CE marking requirements. - [Open Source Hardware](https://cvdportal.com/compliance/open-source-hardware): CRA compliance for open source hardware projects. When is open source hardware in scope? Commercial production vs hobby use, steward responsibilities, and conformity for OSH products. - [Payment Terminals & ATMs](https://cvdportal.com/compliance/payment-terminals): CRA compliance for payment terminal and ATM manufacturers. PCI DSS intersection, PSD2 SCA requirements, and Annex III Class I obligations for financial transaction hardware. - [Perimeter Security & Smart Barriers](https://cvdportal.com/compliance/perimeter-security): CRA compliance for perimeter security and smart barrier manufacturers. Connected vehicle barriers, electric fencing, and perimeter detection systems under the Cyber Resilience Act. - [Point of Sale & Payment Terminals](https://cvdportal.com/compliance/point-of-sale): CRA compliance for POS and payment terminal manufacturers. Intersection with PCI DSS, PSD2 SCA requirements, and Cyber Resilience Act for payment hardware and software. - [Precision Agriculture & Smart Farming](https://cvdportal.com/compliance/precision-agriculture): CRA compliance for precision agriculture and smart farming manufacturers. Covers connected tractors, field sensors, drone sprayers, and farm management software requirements. - [Process Control & SCADA Systems](https://cvdportal.com/compliance/process-control): CRA compliance for SCADA and process control manufacturers. Annex III Class II critical infrastructure requirements, IEC 62443 alignment, and third-party conformity assessment. - [Satellite & Space Technology](https://cvdportal.com/compliance/satellite-space): CRA compliance for satellite and space technology manufacturers. Annex III Class II for ground segment and user terminals. Covers satellite communication systems and space cybersecurity. - [Smart Appliances & White Goods](https://cvdportal.com/compliance/smart-appliances): CRA compliance checklist for smart appliance manufacturers. Covers washing machines, fridges, ovens and other connected white goods under EU Cyber Resilience Act. - [Smart Cameras & Video Surveillance](https://cvdportal.com/compliance/smart-cameras): CRA compliance for IP cameras, smart doorbells, and video surveillance systems. Article 13 CVD obligations, default credential requirements, Annex I security, and CE marking. - [Smart Greenhouse Automation](https://cvdportal.com/compliance/smart-greenhouse): CRA compliance for smart greenhouse automation manufacturers. Climate control systems, irrigation automation, lighting control, and connected greenhouse management platforms. - [Smart Grid & Energy Infrastructure](https://cvdportal.com/compliance/smart-grid): CRA compliance for smart grid and energy infrastructure manufacturers. Annex III Class II for grid-connected systems. Covers smart meters, grid controllers, and NIS2 intersection. - [Smart Home Devices](https://cvdportal.com/compliance/smart-home-devices): Complete CRA compliance checklist for smart home device manufacturers. Covers Article 13 CVD policy, Article 14 reporting, Annex I security requirements, and CE marking obligations. - [Smart Toys & Connected Children's Products](https://cvdportal.com/compliance/smart-toys): CRA compliance for smart toy manufacturers. Annex III Class II requirements for AI-enabled and data-collecting children's products. Third-party conformity assessment required. - [Telecommunications Equipment](https://cvdportal.com/compliance/telecom-equipment): CRA compliance for telecommunications equipment manufacturers. Annex III Class II for core network components. Covers 5G, fixed network equipment, and regulatory intersections. - [Vending Machines & Interactive Kiosks](https://cvdportal.com/compliance/vending-kiosk): CRA compliance for vending machine and interactive kiosk manufacturers. Connected kiosks, payment-integrated vending, self-service terminals, and Cyber Resilience Act requirements. - [Warehouse Automation & Logistics Systems](https://cvdportal.com/compliance/warehouse-logistics): CRA compliance checklist for warehouse automation and logistics system manufacturers. Covers AGVs, WMS software, conveyor control, and connected logistics devices. - [Wearable Devices & Fitness Trackers](https://cvdportal.com/compliance/wearable-devices): CRA compliance for fitness trackers, smartwatches, and health wearables. Article 13 CVD policy, Annex I security requirements, Bluetooth data security, and CE marking. ## Role guides - [Board Director & Executive Leadership](https://cvdportal.com/for/board-director): Board directors and executives bear ultimate accountability for CRA compliance. This guide explains liability exposure, governance frameworks, and the resource allocation decisions required to achieve and maintain conformity under the Cyber Resilience Act. - [Chief Information Security Officer (CISO)](https://cvdportal.com/for/ciso): How CISOs own CVD policy, lead PSIRT operations, execute Article 14 incident reporting, and build the security testing programme required by the EU Cyber Resilience Act. - [Cloud & Backend Engineer](https://cvdportal.com/for/cloud-engineer): Cloud and backend engineers' EU CRA obligations - API security, secure CI/CD, SBOM for backend services, and dependency management for connected products. - [Compliance Officer](https://cvdportal.com/for/compliance-officer): Compliance Officers' CRA obligations: conformity assessment management, Annex IV technical documentation, CE marking process, audit readiness, and monitoring delegated acts. - [Chief Operating Officer (COO)](https://cvdportal.com/for/coo): COO's operational guide to EU CRA compliance - cross-team programme governance, supply chain obligations, and Article 14 incident operational readiness. - [Chief Technology Officer (CTO)](https://cvdportal.com/for/cto): How CTOs lead CRA compliance programmes: SBOM governance, secure update infrastructure, Declaration of Conformity signing authority, and technical architecture obligations. - [Customer Success Manager](https://cvdportal.com/for/customer-success): Customer Success Managers' EU CRA role - customer vulnerability communications, EOL conversations, due diligence requests, and proactive security disclosure. - [DevOps & Platform Engineer](https://cvdportal.com/for/devops-engineer): CRA obligations for DevOps engineers: secure CI/CD pipelines, automated SBOM generation, signed artifact delivery, vulnerability scanning, and OTA update infrastructure. - [Embedded Systems Engineer](https://cvdportal.com/for/embedded-systems-engineer): How embedded systems engineers meet CRA requirements: secure boot, HSM integration, memory safety, hardware CVE triage, and chip-level SBOM for EU market products. - [Firmware & Embedded Software Developer](https://cvdportal.com/for/firmware-developer): Firmware and embedded software developers face direct CRA obligations around secure coding, signed builds, secure boot, and SBOM. This guide explains what the Cyber Resilience Act requires at the firmware layer. - [General Counsel](https://cvdportal.com/for/general-counsel): General Counsel must manage CRA legal exposure, Declaration of Conformity obligations, EU Authorised Representative requirements, NCA enforcement response, and the intersection with the EU Product Liability Directive. This guide covers each area. - [Hardware & PCB Design Engineer](https://cvdportal.com/for/hardware-engineer): Hardware engineers' EU CRA obligations - secure boot, HSM design, hardware SBOM, tamper resistance requirements under Annex I for products with digital elements. - [IT Manager (Internal Tools & Infrastructure)](https://cvdportal.com/for/it-manager): IT managers' EU CRA role - supporting PSIRT infrastructure, internal SBOM and vulnerability tracking tooling, and patch management systems for connected products. - [Legal Counsel & Data Protection Officer](https://cvdportal.com/for/legal-counsel): Legal Counsel's CRA obligations: regulatory interpretation, Declaration of Conformity sign-off, supply chain contract requirements, GDPR overlap, and managing regulator correspondence. - [Open-Source Project Maintainer](https://cvdportal.com/for/open-source-maintainer): Does the CRA apply to open-source projects? The stewardship exemption protects non-commercial maintainers, but commercial OSS projects face obligations. This guide explains the CRA's open-source rules, CVD policy requirements, and SBOM obligations. - [Penetration Tester & Red Team Lead](https://cvdportal.com/for/pen-tester): Penetration testers' EU CRA obligations - using pen test results as conformity evidence, Annex I scope requirements, and coordinating findings with the PSIRT. - [Procurement & Supply Chain Manager](https://cvdportal.com/for/procurement-manager): Procurement managers must enforce CRA supply chain security obligations through vendor contracts, security questionnaires, and SBOM collection. This guide explains what to require from suppliers under the Cyber Resilience Act. - [Product Manager](https://cvdportal.com/for/product-manager): How Product Managers embed CRA requirements into roadmaps, define support lifecycle obligations, manage EOL policy, and communicate security disclosures to users under EU law. - [PSIRT Manager](https://cvdportal.com/for/psirt-manager): PSIRT managers carry the Article 14 notification obligations under the CRA. This guide covers CVD process requirements, the 24h/72h/14-day reporting timeline to ENISA, and CSAF advisory authoring. - [Quality Assurance & Test Engineer](https://cvdportal.com/for/quality-assurance): QA engineers play a direct role in CRA conformity by executing security test coverage, managing vulnerability regression testing, and contributing test evidence to the technical file. This guide explains each obligation. - [Regulatory Affairs Manager](https://cvdportal.com/for/regulatory-affairs): Regulatory Affairs Managers coordinate CRA conformity assessment, NCA relationships, and multi-regulation overlap with NIS2 and MDR. This guide maps the key obligations and governance touchpoints under the Cyber Resilience Act. - [Sales Engineer & Pre-Sales Consultant](https://cvdportal.com/for/sales-engineer): Sales engineers are on the front line when enterprise customers ask about CRA compliance, DoC documentation, and EOL support timelines. This guide prepares you to answer security questionnaires and communicate CRA readiness with confidence. - [Security Analyst & SOC Analyst](https://cvdportal.com/for/security-analyst): Security and SOC analysts' EU CRA role - threat intelligence, CVE monitoring against the SBOM, PSIRT triage escalation, and Article 14 early warning process. - [Security Architect](https://cvdportal.com/for/security-architect): How Security Architects drive EU Cyber Resilience Act compliance - secure-by-design principles, threat modelling, Annex I controls and conformity evidence. - [Security Engineer](https://cvdportal.com/for/security-engineer): Security engineers are at the heart of CRA conformity. This guide covers Annex I technical requirements, SBOM management, CVE triage, and PSIRT collaboration obligations under the Cyber Resilience Act. - [Software Architect](https://cvdportal.com/for/software-architect): Software architects' EU CRA obligations - secure dependency selection, updatability design, data handling architecture, and technical file evidence under Annex I. - [Startup Founder & CEO (First-Time CRA Compliance)](https://cvdportal.com/for/startup-founder): If your startup sells connected hardware or software products into the EU, the Cyber Resilience Act applies to you. This guide explains minimum viable CRA compliance, build vs buy decisions, and how investor due diligence is changing. - [Supply Chain & Vendor Risk Manager](https://cvdportal.com/for/supply-chain-manager): Supply chain managers' EU CRA obligations - vendor security assessments, SBOM collection, open-source governance, and contractual requirements under Annex I §10. - [Technical Writer & Documentation Lead](https://cvdportal.com/for/technical-writer): CRA obligations for technical writers: CVD policy documentation, security.txt authoring, CSAF advisory writing, user-facing vulnerability disclosures, and technical file docs. - [VP of Engineering](https://cvdportal.com/for/vp-engineering): CRA obligations for VPs of Engineering: team readiness, secure SDLC adoption, resource allocation for security work, cross-team vulnerability coordination, and CRA tooling decisions. ## EU country guides - [Austria](https://cvdportal.com/eu/austria): CRA compliance for Austrian manufacturers: GovCERT Austria/BMI as national authority, incident reporting, market surveillance, and alignment with Austrian cybersecurity strategy. - [Belgium](https://cvdportal.com/eu/belgium): CRA compliance for Belgian manufacturers: CCB as national authority, CERT.be incident reporting, market surveillance, and alignment with Belgium's national cybersecurity strategy. - [Bulgaria](https://cvdportal.com/eu/bulgaria): CRA compliance for Bulgarian manufacturers: State e-Government Agency as national authority, CERT Bulgaria incident reporting, market surveillance, and national cybersecurity framework. - [Croatia](https://cvdportal.com/eu/croatia): CRA compliance for Croatian manufacturers: HAKOM as national authority, CERT.hr incident reporting, market surveillance, and Croatian cybersecurity framework alignment. - [Czech Republic](https://cvdportal.com/eu/czech-republic): CRA compliance for Czech manufacturers: NUKIB as national authority, CSIRT.CZ incident reporting, market surveillance, and alignment with Czech cybersecurity law. - [Denmark](https://cvdportal.com/eu/denmark): CRA compliance for Danish manufacturers: SAMSIK as national authority, Article 14 incident reporting, market surveillance, and alignment with Danish cybersecurity strategy. - [Estonia](https://cvdportal.com/eu/estonia): CRA compliance for Estonian manufacturers: RIA as national authority, CERT-EE incident reporting, market surveillance, and Estonia's world-leading digital governance alignment. - [Finland](https://cvdportal.com/eu/finland): CRA compliance for Finnish manufacturers: Traficom/NCSC-FI as national authority, Article 14 incident reporting, market surveillance, and Finnish cybersecurity framework alignment. - [France](https://cvdportal.com/eu/france): CRA compliance for French manufacturers: ANSSI as national authority, CERT-FR incident reporting, market surveillance under French law, and alignment with the Loi de Programmation Militaire. - [Germany](https://cvdportal.com/eu/germany): How German manufacturers comply with the EU Cyber Resilience Act: BSI as the national authority, CERT-Bund incident reporting, market surveillance, and national cybersecurity law alignment. - [Greece](https://cvdportal.com/eu/greece): CRA compliance for Greek manufacturers: Ministry of Digital Governance as national authority, GR-CSIRT incident reporting, market surveillance, and Greek cybersecurity framework alignment. - [Hungary](https://cvdportal.com/eu/hungary): CRA compliance for Hungarian manufacturers: SZTFH as national authority, GovCERT Hungary incident reporting, market surveillance, and alignment with Hungarian cybersecurity law. - [Ireland](https://cvdportal.com/eu/ireland): CRA compliance for Irish manufacturers: NCSC Ireland as national authority, CSIRT-IE incident reporting, market surveillance, and alignment with Ireland's National Cyber Security Strategy. - [Italy](https://cvdportal.com/eu/italy): CRA compliance for Italian manufacturers: ACN as national authority, CSIRT Italia incident reporting, market surveillance, and alignment with Italy's Perimetro di Sicurezza Nazionale Cibernetica. - [Latvia](https://cvdportal.com/eu/latvia): CRA compliance for Latvian manufacturers: CERT.LV as national authority and CSIRT, Article 14 incident reporting, market surveillance, and Latvian cybersecurity framework. - [Lithuania](https://cvdportal.com/eu/lithuania): CRA compliance for Lithuanian manufacturers: NKSC as national authority, CERT-LT incident reporting, market surveillance, and Lithuanian cybersecurity law alignment. - [Luxembourg](https://cvdportal.com/eu/luxembourg): CRA compliance for Luxembourg manufacturers: ILNAS and CIRCL as national authorities, CIRCL incident reporting, market surveillance, and Luxembourg's cybersecurity framework. - [Malta](https://cvdportal.com/eu/malta): CRA compliance for Maltese manufacturers: MDIA/CIPD as national authority, MDIA/CIPD-CSIRT incident reporting, market surveillance, and Malta's national cybersecurity strategy. - [Netherlands](https://cvdportal.com/eu/netherlands): CRA compliance for Dutch manufacturers: NCSC-NL as national authority, Article 14 incident reporting, market surveillance by RDI, and alignment with Dutch cybersecurity frameworks. - [Norway](https://cvdportal.com/eu/norway): CRA compliance for Norwegian manufacturers: NSM as EEA national authority, NorCERT incident reporting, market surveillance, and alignment with Norwegian cybersecurity law. - [Poland](https://cvdportal.com/eu/poland): CRA compliance for Polish manufacturers: CERT Polska/NASK as national authority, Article 14 incident reporting, market surveillance, and alignment with Poland's national cybersecurity framework. - [Portugal](https://cvdportal.com/eu/portugal): CRA compliance for Portuguese manufacturers: CNCS as national authority, CERT.PT incident reporting, market surveillance, and alignment with Portugal's national cybersecurity strategy. - [Romania](https://cvdportal.com/eu/romania): CRA compliance for Romanian manufacturers: DNSC as national authority, incident reporting, market surveillance, and alignment with Romania's national cybersecurity framework. - [Slovakia](https://cvdportal.com/eu/slovakia): CRA compliance for Slovak manufacturers: NBU as national authority, SK-CERT incident reporting, market surveillance, and alignment with Slovak cybersecurity law. - [Slovenia](https://cvdportal.com/eu/slovenia): CRA compliance for Slovenian manufacturers: SI-CERT and AKOS as national authorities, SI-CERT incident reporting, market surveillance, and Slovenian cybersecurity framework. - [Spain](https://cvdportal.com/eu/spain): CRA compliance for Spanish manufacturers: CCN and INCIBE as national authorities, INCIBE-CERT incident reporting, market surveillance, and the Esquema Nacional de Seguridad framework. - [Sweden](https://cvdportal.com/eu/sweden): CRA compliance for Swedish manufacturers: NCSC-SE as national authority, CERT-SE incident reporting, market surveillance, and alignment with Swedish cybersecurity strategy. ## Glossary - [Actively Exploited Vulnerability](https://cvdportal.com/glossary/actively-exploited-vulnerability): What an actively exploited vulnerability means under the CRA, the 24-hour ENISA notification requirement, and how to determine exploitation status. - [Advisory Embargo](https://cvdportal.com/glossary/advisory-embargo): What an advisory embargo is in coordinated vulnerability disclosure, how embargo periods work, and when they may be shortened or broken under CRA obligations. - [Annex I Essential Requirements](https://cvdportal.com/glossary/annex-i-requirements): Understand the CRA's Annex I essential requirements - both Part I product security properties and Part II vulnerability handling obligations - and what they mean for manufacturers. - [Annex II User Information Requirements](https://cvdportal.com/glossary/annex-ii-user-information): What CRA Annex II requires manufacturers to communicate to users - product identifiers, support periods, vulnerability contacts, and security update information. - [Annex III Important Product Classification](https://cvdportal.com/glossary/annex-iii-classification): How the CRA classifies products as Important Class I, Class II, or Critical under Annex III, the criteria for each tier, and what your classification means for conformity assessment. - [Annex VII Technical Documentation File](https://cvdportal.com/glossary/annex-vii-technical-file): What CRA Annex VII requires in a manufacturer's technical documentation file - from risk assessments and SBOMs to CVD policies and test reports. - [Attack Surface](https://cvdportal.com/glossary/attack-surface): What is attack surface in cybersecurity? Learn how the EU Cyber Resilience Act requires manufacturers to minimise attack surface in connected products with digital elements. - [Bug Bounty Programme](https://cvdportal.com/glossary/bug-bounty): What is a bug bounty programme and how does it relate to EU Cyber Resilience Act compliance? Learn the difference between bug bounty and mandatory CVD obligations under the CRA. - [CE Marking (Cybersecurity)](https://cvdportal.com/glossary/ce-marking): Learn what CE marking means in the context of the CRA, what it requires manufacturers to demonstrate, and how it relates to conformity assessment and the Declaration of Conformity. - [CISA Known Exploited Vulnerabilities (KEV) Catalogue](https://cvdportal.com/glossary/cisa-kev): What is the CISA Known Exploited Vulnerabilities (KEV) catalogue? Learn how EU manufacturers must use KEV data to meet EU Cyber Resilience Act notification and patching obligations. - [Common Vulnerability Scoring System (CVSS) - Full Guide](https://cvdportal.com/glossary/common-vulnerability-scoring-system): A complete guide to CVSS for EU Cyber Resilience Act compliance. Learn how CVSS base, temporal, and environmental scores work, and how manufacturers use CVSS in CRA vulnerability management. - [Conformity Assessment](https://cvdportal.com/glossary/conformity-assessment): Understand CRA conformity assessment routes, what each classification requires, and how manufacturers prepare technical documentation for notified body review. - [Conformity Assessment Procedure](https://cvdportal.com/glossary/conformity-assessment-procedure): Learn about CRA conformity assessment procedures - which route applies to your product class, what self-certification covers, and when a Notified Body is required. - [Coordinated Vulnerability Disclosure (CVD)](https://cvdportal.com/glossary/coordinated-vulnerability-disclosure): Learn what Coordinated Vulnerability Disclosure (CVD) means under the EU Cyber Resilience Act, why it is legally required, and how manufacturers must implement it. - [Coordinating CSIRT](https://cvdportal.com/glossary/coordinating-csirt): What a Coordinating CSIRT does under the CRA - how national CSIRTs facilitate multi-party vulnerability disclosures and support CRA Article 14 notification processes. - [Critical Vulnerability](https://cvdportal.com/glossary/critical-vulnerability): What a critical vulnerability is, how CVSS defines the critical severity band, and what CRA-compliant manufacturers must do when one is discovered. - [Cryptographic Agility](https://cvdportal.com/glossary/cryptographic-agility): What cryptographic agility means for CRA-compliant product design, how to implement it, and why post-quantum readiness makes it critical for long-lived products. - [Common Security Advisory Framework (CSAF)](https://cvdportal.com/glossary/csaf): What CSAF is, why ENISA recommends it for CRA compliance, and how manufacturers use CSAF 2.0 to publish machine-readable security advisories instead of PDF bulletins. - [CSIRT - Computer Security Incident Response Team](https://cvdportal.com/glossary/csirt): Learn what CSIRTs are, which national CSIRTs EU manufacturers must notify under Article 14 of the CRA, and how CSIRT coordination works in the EU cybersecurity ecosystem. - [CVD Coordinator](https://cvdportal.com/glossary/cvd-coordinator): What a CVD Coordinator does, when to involve one in multi-vendor vulnerability disclosures, and how ENISA's coordination role works under the Cyber Resilience Act. - [CVD Policy](https://cvdportal.com/glossary/cvd-policy): Understand what a CVD policy must contain under the EU Cyber Resilience Act, how to publish one, and what manufacturers get wrong when drafting their first policy. - [Common Vulnerabilities and Exposures (CVE)](https://cvdportal.com/glossary/cve): Learn what CVE identifiers are, how the CVE programme works, and how EU manufacturers must use CVE in CRA-compliant vulnerability handling and security advisories. - [Common Vulnerability Scoring System (CVSS)](https://cvdportal.com/glossary/cvss): Understand CVSS scoring, how it applies to CRA vulnerability handling obligations, and how manufacturers use CVSS in security advisories and patch prioritisation. - [CVSS v4.0](https://cvdportal.com/glossary/cvss-v4): What CVSS v4.0 changes versus v3.1, the new base metrics for IoT and OT products, and what CRA manufacturers need when adopting the FIRST scoring standard. - [Common Weakness Enumeration (CWE)](https://cvdportal.com/glossary/cwe): What CWE is, how it differs from CVE, and how manufacturers use CWE mappings for threat modelling, root cause analysis, and CRA-compliant secure development. - [EU Cyber Resilience Act (CRA)](https://cvdportal.com/glossary/cyber-resilience-act): Definition of the EU Cyber Resilience Act (Regulation (EU) 2024/2847): what the term means, the scope, key dates, and penalties, in glossary form with links to the full guide. - [CycloneDX](https://cvdportal.com/glossary/cyclonedx): What CycloneDX is, how it supports CRA SBOM requirements, its key features for vulnerability management, and how it compares to SPDX. - [EU Declaration of Conformity (DoC)](https://cvdportal.com/glossary/declaration-of-conformity): Learn what a CRA Declaration of Conformity must contain, who signs it, how long it must be retained, and what triggers the need for a new DoC. - [Default Class Product (CRA)](https://cvdportal.com/glossary/default-class): What is a Default Class product under the EU Cyber Resilience Act? Learn which products qualify, how self-certification works, and what compliance obligations still apply. - [Defence in Depth](https://cvdportal.com/glossary/defence-in-depth): What defence in depth means for CRA product security, how layered controls reduce risk, and how to apply the principle across hardware, firmware, and software. - [Dependency-Track](https://cvdportal.com/glossary/dependency-track): What Dependency-Track is, how it enables continuous SBOM-based vulnerability monitoring for CRA compliance, and how to integrate it into a PSIRT workflow. - [DevSecOps](https://cvdportal.com/glossary/devsecops): What DevSecOps is, how it supports CRA SDLC obligations, and which pipeline security controls are most relevant for manufacturers of CRA-covered products. - [Disclosure Timeline](https://cvdportal.com/glossary/disclosure-timeline): What a vulnerability disclosure timeline means, the industry standard 90-day practice, how grace periods work, and what the CRA expects from manufacturers. - [Economic Operator (CRA)](https://cvdportal.com/glossary/economic-operator): Who are economic operators under the EU Cyber Resilience Act? Understand the obligations of manufacturers, importers, distributors, and authorised representatives. - [End-of-Life Policy](https://cvdportal.com/glossary/end-of-life-policy): What is an end-of-life policy under the EU Cyber Resilience Act? Learn how manufacturers must communicate EOL dates and meet minimum support period requirements for CRA compliance. - [ENISA - EU Agency for Cybersecurity](https://cvdportal.com/glossary/enisa): Learn ENISA's role under the EU Cyber Resilience Act: vulnerability registry operation, Article 14 notifications, guidance publication, and support for manufacturers. - [Exploit Prediction Scoring System (EPSS)](https://cvdportal.com/glossary/epss): What EPSS is, how it differs from CVSS, and how manufacturers use EPSS scores to prioritise vulnerability remediation under CRA compliance requirements. - [Essential Cybersecurity Requirements](https://cvdportal.com/glossary/essential-cybersecurity-requirements): Learn what the CRA's essential cybersecurity requirements cover, how they map to Annex I, and what manufacturers must demonstrate to meet them. - [EU Type-Examination](https://cvdportal.com/glossary/eu-type-examination): Understand EU Type-Examination under the Cyber Resilience Act - what the procedure involves, when it is required for Important Class II products, and how certificates work. - [European Vulnerability Database (EUVDB)](https://cvdportal.com/glossary/european-vulnerability-database): What the EU's European Vulnerability Database (EUVDB) is, how CRA manufacturers must notify it, and how it relates to the US NVD and CVE programme. - [Exploit](https://cvdportal.com/glossary/exploit): Understand what an exploit is, how it relates to vulnerabilities, and why the EU Cyber Resilience Act requires manufacturers to respond before exploits are developed. - [Firmware Update & OTA Security](https://cvdportal.com/glossary/firmware-update): What are firmware updates and OTA security under the EU Cyber Resilience Act? Learn how manufacturers must deliver and secure software updates for connected products. - [Hardware Security Module (HSM)](https://cvdportal.com/glossary/hardware-security-module): What an HSM is, how it protects cryptographic keys in CRA-covered products, and when HSMs are required for secure boot and firmware signing infrastructure. - [Harmonised Standard](https://cvdportal.com/glossary/harmonised-standard): What Harmonised Standards mean for EU Cyber Resilience Act compliance, how they create a presumption of conformity, and which standards bodies are developing CRA standards. - [Important Product Class I](https://cvdportal.com/glossary/important-class-i): What is Important Product Class I under the EU Cyber Resilience Act? Understand which products qualify, the conformity assessment requirements, and compliance obligations. - [Important Product Class II](https://cvdportal.com/glossary/important-class-ii): Which products are Important Class II under the CRA, such as firewalls, IDS/IPS, and tamper-resistant microprocessors, and why they need mandatory third-party conformity assessment. - [Incident Response](https://cvdportal.com/glossary/incident-response): What is incident response under the EU Cyber Resilience Act? Learn how manufacturers must prepare for, manage, and report security incidents affecting products with digital elements. - [Indicator of Compromise (IoC)](https://cvdportal.com/glossary/indicator-of-compromise): What Indicators of Compromise (IoCs) are, how they are used in incident detection and response, and their role in detecting CRA Article 14 notification triggers. - [Principle of Least Privilege](https://cvdportal.com/glossary/least-privilege): What the Principle of Least Privilege means for CRA product design, how it limits exploit impact, and how to implement it across firmware, OS, and application layers. - [Manufacturer Obligations (CRA)](https://cvdportal.com/glossary/manufacturer-obligation): What are manufacturer obligations under the EU Cyber Resilience Act? A complete overview of design, vulnerability handling, reporting, and post-market security duties for EU manufacturers. - [Market Surveillance Authority (MSA)](https://cvdportal.com/glossary/market-surveillance-authority): Understand the role of Market Surveillance Authorities under the EU Cyber Resilience Act - who they are, what powers they hold, and how they enforce CRA compliance. - [Mean Time to Remediate (MTTR)](https://cvdportal.com/glossary/mean-time-to-remediate): What MTTR is, how to calculate it, why it matters for CRA compliance, and benchmark values for different vulnerability severity levels. - [National Vulnerability Database (NVD)](https://cvdportal.com/glossary/national-vulnerability-database): What is the National Vulnerability Database (NVD)? Learn how NVD supports EU Cyber Resilience Act compliance and why it is central to vulnerability management for EU manufacturers. - [Network Segmentation](https://cvdportal.com/glossary/network-segmentation): What network segmentation means for CRA product security design, how it limits exploit blast radius, and what manufacturers must consider for enterprise and OT deployments. - [NIS2 Directive](https://cvdportal.com/glossary/nis2-directive): Understand the NIS2 Directive and its relationship to the EU Cyber Resilience Act - how they differ, where they overlap, and what manufacturers operating digital services must do. - [Notified Body](https://cvdportal.com/glossary/notified-body): Learn what a Notified Body is under the EU Cyber Resilience Act, which product classes require one, and how third-party conformity assessment works for CRA compliance. - [Open Source Component](https://cvdportal.com/glossary/open-source-component): What open source components mean for CRA compliance - manufacturer obligations, SBOM requirements, and how to manage vulnerabilities in open source dependencies. - [Open Source Steward](https://cvdportal.com/glossary/open-source-steward): What the CRA's Open Source Steward category means, which obligations apply, and how it differs from the manufacturer classification for commercial products. - [Open Source Vulnerability (OSV) Format](https://cvdportal.com/glossary/osv): What the OSV format and database are, how they enable SBOM-based vulnerability detection, and why OSV complements NVD for CRA-compliant software composition analysis. - [Over-the-Air (OTA) Update](https://cvdportal.com/glossary/ota-update): What OTA updates are, why they are critical for CRA compliance, and the security requirements for a safe and reliable OTA update mechanism. - [Patch Management](https://cvdportal.com/glossary/patch-management): Learn what patch management means under the EU Cyber Resilience Act, what timelines apply, and how manufacturers must deliver security updates to remain compliant. - [Penetration Testing](https://cvdportal.com/glossary/penetration-testing): Learn what penetration testing is, how it supports EU Cyber Resilience Act compliance, and what manufacturers of products with digital elements must do before market placement. - [Product Liability Directive](https://cvdportal.com/glossary/product-liability-directive): How the revised EU Product Liability Directive interacts with the CRA - why cybersecurity defects in products with digital elements can now trigger civil liability claims. - [Products with Digital Elements (PDE)](https://cvdportal.com/glossary/products-with-digital-elements): Understand what the CRA means by 'products with digital elements', which products are in scope, which are excluded, and how the definition affects manufacturers. - [Proof-of-Concept (PoC) Exploit](https://cvdportal.com/glossary/proof-of-concept): Understand what a proof-of-concept exploit is, how it affects CRA vulnerability response timelines, and what manufacturers must do when a public PoC for their product is released. - [Product Security Incident Response Team (PSIRT)](https://cvdportal.com/glossary/psirt): What a Product Security Incident Response Team (PSIRT) does, how it differs from a CSIRT, and the PSIRT capabilities the EU Cyber Resilience Act requires manufacturers to maintain. - [Package URL (PURL)](https://cvdportal.com/glossary/purl): What a Package URL (PURL) is, why it matters for SBOM accuracy, and how PURLs enable CRA-compliant vulnerability management through precise component identification. - [Radio Equipment Directive (RED)](https://cvdportal.com/glossary/red-directive): Understand the Radio Equipment Directive and its cybersecurity requirements - how RED Article 3.3(d)(e)(f) relates to CRA compliance for wireless and connected devices. - [Remediation Timeline](https://cvdportal.com/glossary/remediation-timeline): What remediation timelines mean for CRA compliance - how to set severity-based SLAs, what 'without undue delay' means in practice, and how to measure performance. - [Responsible Disclosure](https://cvdportal.com/glossary/responsible-disclosure): Understand responsible disclosure, how it relates to coordinated vulnerability disclosure under the CRA, and what obligations it creates for EU manufacturers. - [Cybersecurity Risk Assessment](https://cvdportal.com/glossary/risk-assessment): What is a cybersecurity risk assessment under the EU Cyber Resilience Act? Learn what manufacturers must document, assess, and mitigate before placing products on the EU market. - [Safe Harbour Clause](https://cvdportal.com/glossary/safe-harbour-clause): What a safe harbour clause is in a CVD policy, why it is essential for CRA compliance, and how manufacturers should draft one to protect good-faith security researchers. - [Software Bill of Materials (SBOM)](https://cvdportal.com/glossary/sbom): Learn what an SBOM is, why the EU Cyber Resilience Act requires one, which formats to use, and how manufacturers maintain SBOMs for CRA compliance. - [Secure Development Lifecycle (SDLC)](https://cvdportal.com/glossary/sdlc): What a Secure Development Lifecycle is, which SDLC activities are required for CRA compliance, and how to implement SDLC practices in hardware and software product development. - [Secure Boot](https://cvdportal.com/glossary/secure-boot): What Secure Boot is, how it prevents firmware tampering, and why it is an essential security requirement for CRA-covered embedded and IoT products. - [Secure by Default](https://cvdportal.com/glossary/secure-by-default): What does 'secure by default' mean under the EU Cyber Resilience Act? Learn how Annex I requires manufacturers to ship products with security enabled out of the box. - [Secure by Design](https://cvdportal.com/glossary/secure-by-design): What does 'secure by design' mean under the EU Cyber Resilience Act? Learn how Annex I requires manufacturers to embed security throughout the product development lifecycle. - [Security Advisory](https://cvdportal.com/glossary/security-advisory): Learn what a CRA-compliant security advisory must contain, why CSAF format is preferred, and how to publish advisories effectively for EU regulatory compliance. - [Security Researcher](https://cvdportal.com/glossary/security-researcher): Who is a security researcher under the EU Cyber Resilience Act? Learn how the CRA protects researchers, what manufacturers owe them, and the role researchers play in CRA compliance. - [security.txt](https://cvdportal.com/glossary/security-txt): Learn what security.txt is, how it relates to EU CRA compliance, and how to create an RFC 9116-compliant security.txt file for your product's domain. - [Security Information and Event Management (SIEM)](https://cvdportal.com/glossary/siem): What SIEM is, how it supports CRA compliance through incident detection and audit logging, and which log sources are most relevant for manufacturers of CRA-covered products. - [Security Operations Centre (SOC)](https://cvdportal.com/glossary/soc): What a Security Operations Centre does, how it supports CRA compliance for product manufacturers, and when internal vs managed SOC services are appropriate. - [Software Composition Analysis (SCA)](https://cvdportal.com/glossary/software-composition-analysis): What is Software Composition Analysis (SCA) and how does it support EU Cyber Resilience Act compliance? Learn how manufacturers use SCA to manage open-source vulnerabilities. - [Software Identifier](https://cvdportal.com/glossary/software-identifier): What software identifiers are, how CPE, PURL, and SWID tags differ, and why precise identification matters for CRA-compliant SBOM and vulnerability management. - [SPDX (Software Package Data Exchange)](https://cvdportal.com/glossary/spdx): What SPDX is, how it supports CRA SBOM requirements, its ISO standardisation status, and how it compares to CycloneDX for product security compliance. - [Software Supply Chain Security](https://cvdportal.com/glossary/supply-chain-security): What is software supply chain security and how does the EU Cyber Resilience Act regulate it? Key obligations for manufacturers using open-source or third-party components. - [Support Period (CRA)](https://cvdportal.com/glossary/support-period): What is the support period under the EU Cyber Resilience Act? Learn the minimum 5-year requirement, how it is calculated, and how manufacturers must communicate it to buyers. - [Technical Documentation (CRA)](https://cvdportal.com/glossary/technical-documentation): Learn what the CRA requires in technical documentation, which records manufacturers must keep, how long to retain them, and how to structure a compliant documentation package. - [Threat Actor](https://cvdportal.com/glossary/threat-actor): What threat actors are, how different actor types pose different risks to CRA-covered products, and how to use threat actor profiles in CRA-required risk assessments. - [Threat Intelligence](https://cvdportal.com/glossary/threat-intelligence): What threat intelligence is, how it supports CRA compliance through threat modelling and exploitation monitoring, and the key sources manufacturers should use. - [Threat Modeling](https://cvdportal.com/glossary/threat-modeling): What is threat modeling and how does it support EU Cyber Resilience Act compliance? Learn how manufacturers use threat modeling to satisfy CRA risk assessment and secure-by-design obligations. - [Transitive Dependency](https://cvdportal.com/glossary/transitive-dependency): What transitive dependencies are, why they create hidden vulnerability exposure in CRA-covered products, and how SBOM practices can surface and manage them. - [Security Triage](https://cvdportal.com/glossary/triage): How to triage and prioritise incoming security reports in a PSIRT, build a CRA-ready triage workflow, and use CVSS and EPSS to rank vulnerabilities by risk. - [VEX - Vulnerability Exploitability eXchange](https://cvdportal.com/glossary/vex-document): What is a VEX document and why does it matter for EU Cyber Resilience Act compliance? Learn how VEX helps manufacturers communicate exploitability status of vulnerabilities in their products. - [Vulnerability Disclosure Policy (VDP)](https://cvdportal.com/glossary/vulnerability-disclosure-policy): What a Vulnerability Disclosure Policy (VDP) is, what it must contain for CRA compliance, and how it differs from a bug bounty programme. - [Vulnerability Handling](https://cvdportal.com/glossary/vulnerability-handling): Learn what CRA-compliant vulnerability handling requires, what processes manufacturers must establish, and how Annex I Part II defines the mandatory obligations. - [Vulnerability Scanning](https://cvdportal.com/glossary/vulnerability-scanning): What is vulnerability scanning and how does it support EU Cyber Resilience Act compliance? Learn how manufacturers use automated scanning to meet ongoing security monitoring obligations. - [Vulnerability Triage](https://cvdportal.com/glossary/vulnerability-triage): What vulnerability triage involves, how CVSS and EPSS are used to prioritise, and how triage feeds CRA-compliant vulnerability handling workflows. - [Security War Room / Incident Bridge](https://cvdportal.com/glossary/war-room): What a security war room is, how to structure one for CRA-relevant incidents, and how war room activities connect to CRA Article 14 notification obligations. - [Zero-Day Vulnerability](https://cvdportal.com/glossary/zero-day): Learn what a zero-day vulnerability is, how it differs from other vulnerabilities, and what the EU Cyber Resilience Act requires manufacturers to do when one is exploited. ## Free tools - [Article 14 Deadline Calculator](https://cvdportal.com/tools/article-14-timeline): Calculate your CRA Article 14 notification deadlines instantly. Enter when you became aware of an actively exploited vulnerability and get your 24-hour, 72-hour, and 14-day ENISA reporting deadlines. - [CRA Vulnerability Disclosure Readiness Check](https://cvdportal.com/tools/cra-readiness-score): Are you ready to receive, handle and report vulnerabilities under the CRA? Answer 20 questions on your coordinated disclosure and Article 14 reporting process and get a readiness score with prioritised gaps. - [CSAF 2.0 Advisory Validator](https://cvdportal.com/tools/csaf-validator): Validate your CSAF 2.0 security advisory JSON against the required schema. Check for missing mandatory fields, invalid structure, and CRA Annex I compliance indicators. - [CVD Policy Generator](https://cvdportal.com/tools/cvd-policy-generator): Generate a ready-to-publish coordinated vulnerability disclosure policy in minutes. Step-by-step wizard covering CRA Article 13 obligations, response timelines, and CSAF commitments. - [CVSS 4.0 Calculator](https://cvdportal.com/tools/cvss-4-calculator): Free CVSS v4.0 calculator covering Base, Threat and Environmental metrics, with the MacroVector shown so the score can be checked. Scoring is a port of the FIRST.ORG reference implementation. No signup. - [CVSS Calculator](https://cvdportal.com/tools/cvss-calculator): Calculate CVSS 3.1 vulnerability severity scores with CRA Article 14 context. Free tool - select base metrics and get your score, severity rating, and Article 14 notification threshold assessment. - [Disclosure Deadline Tracker](https://cvdportal.com/tools/disclosure-deadline-tracker): Track every CRA Article 14 ENISA notification deadline and researcher 90-day embargo from a single report date. Colour-coded UPCOMING / DUE TODAY / OVERDUE status for each milestone. - [Article 14 Notification Template Builder](https://cvdportal.com/tools/notification-template-builder): Generate a complete CRA Article 14 early-warning notification draft for ENISA in seconds. Fill in product, CVE, exploitation status, and affected users - get a submission-ready text block. - [SBOM Component CVE Checker](https://cvdportal.com/tools/sbom-checker): Paste your component list (package@version or CPE format) and generate direct NVD CVE search links for each component. Fast triage for your SBOM against known vulnerability databases. - [SBOM Validator (BSI TR-03183-2 and CISA 2026 Minimum Elements)](https://cvdportal.com/tools/sbom-validator): Validate your CycloneDX or SPDX SBOM against two frameworks side by side: BSI TR-03183-2 format versions and required fields, and the 2026 CISA Minimum Elements with its 17 data fields. Runs in your browser, nothing is uploaded. - [security.txt Generator](https://cvdportal.com/tools/security-txt-generator): Generate a compliant security.txt file for your product or website in seconds. Free tool - fills all RFC 9116 fields including CRA-required contact and policy URLs. ## Policy templates - [Article 14 Early Warning Notification Template](https://cvdportal.com/templates/article-14-notification-template): A free Article 14 early warning notification template for EU manufacturers. Use this to notify ENISA within 24 hours of discovering an actively exploited vulnerability, as required by the Cyber Resilience Act. - [Coordinated Vulnerability Disclosure Policy Template](https://cvdportal.com/templates/coordinated-disclosure-policy): A free coordinated vulnerability disclosure (CVD) policy template aligned with ISO/IEC 29147 and the EU Cyber Resilience Act. Covers disclosure timelines, safe harbour, and researcher coordination. - [Basic CVD Policy Template](https://cvdportal.com/templates/cvd-policy-basic): Download a free coordinated vulnerability disclosure policy template aligned with ISO/IEC 29147. Ready to customise - used by EU manufacturers to meet CRA Article 13 obligations. - [CVD Policy Template for Contract Manufacturers](https://cvdportal.com/templates/cvd-policy-contract-manufacturer): A free CVD policy template for contract manufacturers (EMS/ODM providers) building products on behalf of brand owners. Covers CRA Article 13 obligations, brand owner coordination, and manufacturing process security. - [CRA-Compliant CVD Policy Template](https://cvdportal.com/templates/cvd-policy-cra-compliant): A free vulnerability disclosure policy template that meets EU Cyber Resilience Act Articles 13 and 14. Includes Article 14 notification timelines, CSAF advisory language, and supply chain coordination. - [CVD Policy Template for Industrial and OT Manufacturers](https://cvdportal.com/templates/cvd-policy-industrial): A free CVD policy template for industrial control system and operational technology manufacturers. Covers CRA Article 13/14, ICS-CERT coordination, operational continuity, and critical infrastructure obligations. - [CVD Policy Template for IoT Manufacturers](https://cvdportal.com/templates/cvd-policy-iot): A free vulnerability disclosure policy template for IoT and connected device manufacturers. Addresses CRA Article 13 obligations, firmware update requirements, and constrained-device considerations. - [CVD Policy Template for Medical Device Manufacturers](https://cvdportal.com/templates/cvd-policy-medical): A free vulnerability disclosure policy template for medical device manufacturers. Addresses CRA, MDR, and FDA Cybersecurity guidance obligations including patient safety escalation and regulatory notification. - [CVD Policy Template for OEM Manufacturers](https://cvdportal.com/templates/cvd-policy-oem): A free CVD policy template for OEM manufacturers supplying components to branded product makers. Covers CRA supply chain obligations, upstream/downstream coordination, and component-level vulnerability disclosure. - [EU Declaration of Conformity Template (CRA Annex V)](https://cvdportal.com/templates/declaration-of-conformity-template): A free EU Declaration of Conformity template based on CRA Annex V. One section per required field, with practical guidance for manufacturers drawing up the DoC under Article 28 before CE marking. - [EU CVD Policy Template](https://cvdportal.com/templates/eu-cvd-policy): A free coordinated vulnerability disclosure policy template for EU manufacturers under the Cyber Resilience Act. Covers Article 13 obligations, ENISA reporting, and researcher safe harbour. - [PSIRT Charter Template](https://cvdportal.com/templates/psirt-charter): A free PSIRT charter template for establishing a Product Security Incident Response Team. Defines mandate, scope, roles, and escalation procedures aligned with CRA Article 13 and ISO/IEC 30111. - [Responsible Disclosure Policy Template](https://cvdportal.com/templates/responsible-disclosure-policy): A free responsible disclosure policy template for manufacturers and software companies. Covers researcher commitments, safe harbour, and disclosure timelines. CRA Article 13 compliant. - [Agricultural IoT gateway CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-agricultural-iot): A free CRA risk assessment starter for agriculture: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Vehicle telematics backend CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-automotive-oem): A free CRA risk assessment starter for automotive: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Network management system CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-enterprise-networking): A free CRA risk assessment starter for enterprise networking: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Firewall / IDS-IPS appliance CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-firewall-appliance): A free CRA risk assessment starter for network security: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Industrial controller (PLC) CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-industrial-automation): A free CRA risk assessment starter for industrial automation: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Mobile robot controller CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-robotics): A free CRA risk assessment starter for robotics: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Smart home security hub CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-smart-home): A free CRA risk assessment starter for consumer iot: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Smart meter gateway CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-smart-meter): A free CRA risk assessment starter for energy metering: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Carrier router / CPE CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-telecom-equipment): A free CRA risk assessment starter for telecommunications: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Network camera / NVR CRA Risk Assessment Starter](https://cvdportal.com/templates/risk-assessment-starter-video-surveillance): A free CRA risk assessment starter for video surveillance: classification, asset inventory, 10 STRIDE threats and risk criteria you can copy or seed straight into CVD Portal. - [Security Incident Notification Policy Template](https://cvdportal.com/templates/security-incident-notification): A free security incident notification policy for EU manufacturers under the Cyber Resilience Act. Covers internal escalation, ENISA notification, and user communication procedures. - [security.txt Template (RFC 9116)](https://cvdportal.com/templates/security-txt-template): Free security.txt generator following RFC 9116. Fill in the contact, expires, and policy fields to meet the CRA Article 13 point-of-contact requirement and help researchers reach you. - [CRA Technical Documentation Template (Annex VII)](https://cvdportal.com/templates/technical-documentation-template): A free CRA technical documentation template structured around Annex VII. Assemble the technical file market surveillance authorities can request, from product description and risk assessment to test reports and the EU Declaration of Conformity. - [CRA User Information Template (Annex II)](https://cvdportal.com/templates/user-information-template): A free template for the CRA Annex II information and instructions supplied with products with digital elements. Covers the vulnerability reporting contact, support period end date, DoC access, and secure use instructions. - [Vulnerability Reporting Process Template](https://cvdportal.com/templates/vulnerability-reporting-process): A free internal vulnerability reporting process template for security teams. Covers intake, triage, severity scoring, remediation tracking, and Article 14 escalation under the EU Cyber Resilience Act. ## Competitor comparisons - [CVD Portal vs HackerOne](https://cvdportal.com/compare/hackerone): Crowdsourced vulnerability discovery aimed at large security teams. - [CVD Portal vs Bugcrowd](https://cvdportal.com/compare/bugcrowd): Crowdsourced security testing across bounty, VDP, and pentest formats. - [CVD Portal vs Intigriti](https://cvdportal.com/compare/intigriti): European crowdsourced security platform with a curated researcher community. - [CVD Portal vs YesWeHack](https://cvdportal.com/compare/yeswehack): European bug bounty, VDP, and attack surface platform. - [CVD Portal vs Open Bug Bounty](https://cvdportal.com/compare/openbugbounty): Free community-run platform for coordinated web vulnerability disclosure. - [CVD Portal vs disclose.io](https://cvdportal.com/compare/disclose-io): Community-maintained safe-harbor language and CVD policy templates. - [CVD Portal vs Vicarius](https://cvdportal.com/compare/vicarius): Vulnerability remediation platform focused on patch deployment. - [CVD Portal vs VulnCheck](https://cvdportal.com/compare/vulncheck): Vulnerability intelligence, exploit data, and KEV-style enrichment. - [CVD Portal vs Vanta](https://cvdportal.com/compare/vanta): Compliance automation for organisation-level frameworks such as SOC 2 and ISO 27001. - [CVD Portal vs Drata](https://cvdportal.com/compare/drata): Continuous control monitoring and multi-framework compliance automation for security teams. - [CVD Portal vs CRA consulting](https://cvdportal.com/compare/cra-consulting): Expert-led CRA readiness delivered as an engagement rather than as a system. ## Blog - [The ETSI EN 304 Series: One CRA Standard Per Annex III Product Category](https://cvdportal.com/blog/etsi-en-304-vertical-cra-standards): Everyone tracking CRA standardisation is watching the horizontal prEN 40000 series. The other half of standardisation request M/606 is 18 vertical standards, EN 304 617 to EN 304 642, one per Annex III product category, and ETSI has public drafts out for most of them. Here is the full mapping, the categories ETSI is not covering, and why none of it changes your Article 32 route yet. - [The 2026 SBOM Minimum Elements: What Changed, and Where It Collides With the CRA](https://cvdportal.com/blog/sbom-minimum-elements-2026-what-changed): CISA and seventeen partner agencies, seven of them EU national authorities, have replaced the 2021 NTIA SBOM minimum elements. The field count goes from seven to seventeen, Supplier Name becomes Component Producer, and Depth becomes Coverage with no minimum depth. That last change means a CRA-minimal SBOM fails the new baseline by construction. Here is the full delta, and why your SBOM can now pass one framework and fail another. - [Every Worked Example in the Commission's CRA Guidance, and What Changed From the Draft](https://cvdportal.com/blog/commission-cra-guidance-worked-examples): C(2026) 5252 carries 67 numbered examples and 5 remote data processing use cases. Fourteen of them are new since the consultation draft and one was deleted. Here is what the additions tell you about where the Commission thinks manufacturers are getting it wrong. - [The Commission's CRA Guidance: Reading the Four-Factor Test and the Support Period Rules](https://cvdportal.com/blog/cra-commission-guidance-substantial-modification-support-period): C(2026) 5252 gives manufacturers two things they have been working without. A four-factor test for whether a software update is a substantial modification, and a clear statement that five years of support is a floor rather than a default. This walks through both using the Commission's own worked examples. - [What an Empty Risk Assessment Leaves Out](https://cvdportal.com/blog/cra-risk-assessment-blank-page-problem): A CRA risk assessment has to be the manufacturer's own determination, which is the strongest argument for starting from an empty document. The trouble is what an empty document selects for. Teams write down the threats they already discuss and leave out the interface nobody owns, the decommissioning path, and the failure that only appears at fleet scale. What a starting draft is for, and the one property it needs to stay safe. - [Your CRA Technical File Is Mostly Written Already](https://cvdportal.com/blog/mapping-existing-documents-to-cra-requirements): Most manufacturers approaching the CRA technical file treat it as a writing project. It is a mapping project first. Annex VII asks you to demonstrate that specific evidence satisfies specific essential requirements, and the architecture diagrams, test reports and user documentation that demonstrate them usually already exist. Here is why the mapping is the hard part, and why a gap list computed before mapping measures the wrong thing. - [Your CRA Evidence Already Lives in Jira: Importing It Instead of Rewriting It](https://cvdportal.com/blog/importing-cra-evidence-from-jira-and-confluence): Annex VII asks for records of work that engineering teams already produce, in tickets and wiki pages. Most compliance tooling asks you to transcribe that record into a second set of documents, which then starts decaying immediately. CVD Portal now reads Jira and Confluence directly, so the technical file is built from the systems where the work actually happened. - [Keeping CRA Documentation Up to Date: What the Regulation Actually Requires](https://cvdportal.com/blog/keeping-cra-documentation-up-to-date): The CRA makes the technical file, the risk assessment and the EU Declaration of Conformity living documents. Article 31(2) says continuously updated, Article 13(3) says updated during the support period, and market surveillance can ask for the file a decade later. Here are the update duties, the events that trigger them, and a cadence that survives an inspection. - [Running the CRA Risk Assessment in Practice: CVD Portal and Draft prEN 40000-1-2](https://cvdportal.com/blog/risk-assessment-in-practice-en-40000-1-2): Article 13 requires a documented cybersecurity risk assessment, and the draft European standard prEN 40000-1-2 describes the process a manufacturer should run to produce one. This post walks through how that process works in CVD Portal's products workspace, from product context and risk acceptance criteria to the Annex I applicability table, and maps every step to the regulation and to the draft standard's clauses. - [What the New Joint CISA CVD Guidance Means for CRA Manufacturers](https://cvdportal.com/blog/cisa-cvd-guidance-cra-manufacturers): Five national cyber agencies published a joint guide on working with security researchers. It reads like a checklist for the CRA's vulnerability handling requirements. Here is the mapping, and what to do about each recommendation. - [Running a Bug Bounty Programme Alongside Your CVD Process](https://cvdportal.com/blog/running-a-bug-bounty-programme-alongside-cvd): Bug bounties pay researchers for valid reports. The CRA does not require them, but it does require a coordinated vulnerability disclosure policy. Here is how the two approaches relate, what CVD Portal provides as the disclosure layer, and how AI triage keeps up when report volume grows. - [Annex II in Practice: The User Information the CRA Makes You Publish](https://cvdportal.com/blog/annex-ii-user-information-in-practice): Annex II of the Cyber Resilience Act prescribes the information and instructions every product with digital elements must ship with, from the vulnerability reporting contact to the support period end date. Here is each required item with practical examples, where the information must live, and the mistakes market surveillance will notice first. - [CE Marking Under the Cyber Resilience Act: What Changes for Manufacturers](https://cvdportal.com/blog/ce-marking-under-the-cra): From 11 December 2027 the CE mark on a product with digital elements attests cybersecurity conformity. Here are the Article 30 affixing rules, when a notified body number must accompany the mark, the sequence that must be complete before you affix it, and what market surveillance does about a wrongly marked product. - [The CRA Cybersecurity Risk Assessment: A Working Methodology](https://cvdportal.com/blog/cra-product-risk-assessment-methodology): Article 13 makes a documented cybersecurity risk assessment the foundation of every CRA conformity claim. Here is a working methodology, from STRIDE threat modelling per component and data flow to likelihood and impact scoring, and how the results decide which Annex I requirements apply. - [The Complete CRA Guide for SMEs: Every Obligation in One Place](https://cvdportal.com/blog/cra-sme-guide-complete-obligations): A single walkthrough of every Cyber Resilience Act obligation for a small manufacturer, from the first scope check through classification, Module A self-assessment, documentation, and CE marking to the reporting duties that begin on 11 September 2026. ## News - [ENISA Publishes SRP Registration and Notification Guidance](https://cvdportal.com/news/enisa-srp-registration-guidance): Filing an Article 14 notification requires an EU Login account, your coordinating CSIRT has to validate your reporters after you first sign in, and ENISA has confirmed there will be no submission API. All three have lead times, and the platform opens on the same day the 24-hour clock starts. - [ENISA Publishes a Secure by Design and Default Playbook](https://cvdportal.com/news/enisa-secure-by-design-playbook): Twenty-two playbooks covering secure by design and secure by default across a product life cycle, aimed at SMEs and published on GitHub under CC BY 4.0. It is ENISA guidance rather than a harmonised standard, so applying it confers no presumption of conformity. - [CISA Publishes the 2026 SBOM Minimum Elements, Co-Signed by Seven EU Authorities](https://cvdportal.com/news/cisa-2026-sbom-minimum-elements): Version 2.1 replaces the 2021 NTIA baseline and takes the field count from seven to seventeen. It is not Union law. Seven EU national cybersecurity agencies co-authored it anyway, so expect procurement to follow it, and an SBOM built to the CRA floor fails it by construction. - [ETSI Opens Public Drafts of the EN 304 Vertical CRA Standards](https://cvdportal.com/news/etsi-en-304-vertical-standards): ETSI TC CYBER has published draft Cyber Resilience Act standards for anti-malware software, firewalls, routers, hypervisors and other Annex III product categories, the first of 18 product-specific deliverables under standardisation request M/606. - [Commission Adopts Its Guidance on Applying the Cyber Resilience Act](https://cvdportal.com/news/commission-cra-guidance-adopted): C(2026) 5252 sets out the Commission's own reading of the CRA across 84 pages and 67 worked examples. It defines when the Article 14 reporting clock starts, gives a four-factor test for substantial modification, and confirms that five years of support is a floor rather than a default. - [Why CRA Documentation Never Stops Being Due](https://cvdportal.com/news/keeping-cra-documentation-up-to-date): Article 31(2) requires the technical file to be continuously updated during the support period, Article 13(3) puts the same clock on the risk assessment, and Article 28 keeps the Declaration of Conformity current. A new walkthrough covers the update duties, the trigger events and a review cadence that holds up. - [Five Cyber Agencies Publish Joint CVD Guidance, and It Reads Like a CRA Checklist](https://cvdportal.com/news/cisa-cvd-guidance-cra-manufacturers): CISA, NSA, JPCERT/CC, NCSC-NL, and NCSC-UK published a joint guide on establishing a coordinated vulnerability disclosure programme. It names the EU Cyber Resilience Act directly. - [Five National Cyber Agencies Publish Joint Guide on Establishing a CVD Program. Here Is How CVD Portal Measures Up](https://cvdportal.com/news/joint-guide-cvd-program-security-researchers): CISA, NSA, JPCERT/CC, NCSC-NL and NCSC-UK released joint guidance on building a coordinated vulnerability disclosure program. We mapped every recommendation against CVD Portal. - [Bug Bounty or CVD? What the CRA Requires and How to Run Both](https://cvdportal.com/news/running-a-bug-bounty-programme-alongside-cvd): The CRA requires a coordinated vulnerability disclosure policy, a bug bounty is optional. Our new guide explains how the two approaches relate and how AI triage keeps up when report volume grows. - [CVD Portal at GITEX Europe Berlin 2026](https://cvdportal.com/news/cvdportal-at-gitex-europe-2026): CVD Portal will be at GITEX AI Europe in Berlin on 30 June and 1 July 2026, stand H2.2-B90 at Messe Berlin. Come see how manufacturers run Coordinated Vulnerability Disclosure and meet the EU Cyber Resilience Act reporting obligations that start applying on 11 September 2026. ## API and machine-readable resources - [Documentation](https://docs.cvdportal.com): Product guides for CVD Portal, including the CRA conformity workspace. - [API reference](https://docs.cvdportal.com/cvd/api-overview): REST API developer guide (v1, Bearer auth). - [OpenAPI specification](https://cvdportal.com/openapi.json): Machine-readable REST API spec (v1, Bearer auth, Enterprise plan). - [API catalog](https://cvdportal.com/.well-known/api-catalog): RFC 9727 linkset to spec, docs, and status. - [Security policy](https://cvdportal.com/.well-known/security.txt): RFC 9116 disclosure contact. - [RSS feed](https://cvdportal.com/feed.xml): Latest blog posts and product news. - [Sitemap](https://cvdportal.com/sitemap.xml): Full URL index.