Research
Most claims about Cyber Resilience Act readiness are assertions. These are measurements. Every study here names its sampling frame, publishes what it could not determine as well as what it could, ships the dataset under an open licence, and names no individual company.
Reports
CRA Exposure Study 2026
342 EU manufacturers across eight sectors, scanned for the two artifacts that make a vulnerability report possible. 7% publish a security.txt that meets RFC 9116, weeks before Article 14 applies.
Read the studyCRA Standards Progress
Per-deliverable status of all 18 ETSI EN 304 vertical standards, mapped to every Annex III and Annex IV point. 17 have a public draft and 10 are in the approval procedure. None is cited in the Official Journal, so Article 27 presumption is available for no category.
Read the dataDatasets
CRA Exposure Study 2026 dataset
The full aggregate results with the method carried inside the file. Reuse it with attribution.
CVD Portal, "CRA Exposure Study 2026: coordinated vulnerability disclosure readiness among EU manufacturers", 2026-07-29. https://cvdportal.com/research/cra-exposure-2026 (CC BY 4.0)
CRA Standards Progress dataset
Every ETSI EN 304 deliverable with its work item reference, work programme status, approval date, permanent published PDF, public draft repository and Official Journal citation state. Sources carried inside the file.
CVD Portal, "CRA Standards Progress: the ETSI EN 304 vertical series under standardisation request M/606", 2026-09-01. https://cvdportal.com/research/cra-standards-progress (CC BY 4.0)
The research property
The datasets are published in full on the CRA Data Institute at cradata.eu, a research property of CVD Portal operated by Porta Regulus B.V. The same files are served here and there, so a figure on the page and a figure in the dataset cannot drift apart.
CRA deadline briefing
A short email on the Cyber Resilience Act reporting obligations and the run-up to 11 September 2026.
We use your email only to send the briefing. Unsubscribe any time with one click.