CRA guides
Plain-language, source-backed guides on the Cyber Resilience Act, no fear-mongering, no jargon, no sales pitch disguised as advice.
CRA compliance, explained for manufacturers
Who is in scope, the 2026/2027 deadlines, what you must produce, and a practical path, without building a security team.
SBOM requirements under the CRA
What the regulation actually mandates, CycloneDX vs SPDX, and why the hard part is keeping the SBOM alive, not generating it.
The 24h / 72h reporting timeline
What triggers a mandatory ENISA report, how the clock runs, and the five things to prepare before September 11, 2026.
The CE technical file (Annex VII)
What the technical documentation must contain, how long you must keep it, and why it has to stay current for the whole support period.