Nordchecks
CRA Guides
Plain-language guides to the EU Cyber Resilience Act — scope, risk classes, deadlines, and what it takes to comply.
Gilt der CRA für Nicht-EU-Unternehmen?
Ja — der EU Cyber Resilience Act ist marktbasiert, nicht sitzbasiert. Wenn Sie ein Produkt mit digitalen Elementen in die EU verkaufen, gilt er, egal wo Ihr Unternehmen ansässig ist.
Does the CRA apply to non-EU companies?
Yes — the EU Cyber Resilience Act is market-based, not establishment-based. If you sell a product with digital elements into the EU, it applies wherever your company is based.
The CRA in numbers: deadlines, fines and key figures
Every EU Cyber Resilience Act number that matters in one place — the phase-in dates, the 24/72-hour/14-day reporting windows, the fine tiers, the risk-class split and the support period, each with its source.
CRA Annex VII: the technical documentation, explained section by section
A plain-language walk through Annex VII of the EU Cyber Resilience Act: the eight elements your technical documentation must contain, what artifact satisfies each, and how the file connects to CE marking.
CRA for machine builders: your first SBOM without a dev team
A step-by-step first-SBOM walkthrough for machine builders with no software team: inventory the firmware, PLC/HMI and industrial PC, collect supplier SBOMs, and assemble a CycloneDX list by hand.
CRA compliance cost: what small manufacturers actually pay
An honest breakdown of CRA compliance cost for a small manufacturer — consultants and notified bodies vs a DIY open-source stack vs dedicated software — plus the real cost of non-compliance.
CRA-Compliance-Software: worauf Sie achten sollten
Eine Einkaufs-Checkliste für Cyber-Resilience-Act-Compliance-Software: die sechs Fähigkeiten, die wirklich zählen — SBOM, tägliches Monitoring, 24-Stunden-Meldung, Anhang-VII-Dokumente, Selbstbewertung und faire Preise.
Cyber Resilience Act compliance software: what to look for
A buyer's checklist for cyber resilience act compliance software: the six capabilities that actually matter — SBOM, daily monitoring, 24h reporting, Annex VII docs, self-assessment and fair pricing.
CRA-Vorfallsmeldung: die Fristen von 24 Stunden, 72 Stunden und 14 Tagen
Die CRA-Meldepflicht läuft nach einer festen Uhr: Frühwarnung in 24 Stunden, Meldung in 72 Stunden, Abschlussbericht in 14 Tagen — Wochenenden inklusive. Wann die Uhr startet und an wen Sie melden.
CRA incident reporting: the 24h / 72h / 14-day clock
The CRA reporting duty runs on a fixed clock — early warning in 24 hours, notification in 72 hours, final report in 14 days, weekends included. When the clock starts, what each stage contains, and who you report to.
What to do with a vulnerability finding: CRA triage explained
Your scanner flagged a CVE — now what? The CRA triage flow: assess severity and reachability, then decide fix-now, planned fix, not applicable, or accepted risk — and record every decision as the compliance artifact.
How to automate CRA compliance (instead of managing it in spreadsheets)
The EU Cyber Resilience Act means ongoing work: SBOMs per release, daily vulnerability monitoring, 24h reporting readiness and technical documentation. Here's how to automate it — and stop tracking it by hand.
CRA product classes explained: Default, Important (I & II) and Critical in plain English
The EU Cyber Resilience Act sorts products into risk classes that decide how you prove compliance — self-assessment or a notified body. Which class your product falls in, with plain examples, and why most products are Default.
CRA-Konformität: der praktische Leitfaden für kleine Hersteller
Was der EU Cyber Resilience Act von Ihnen verlangt — verständlich erklärt. Die Anforderungen, die zwei Fristen (11. September 2026 und 11. Dezember 2027) und ein realistischer Weg zur CRA-Konformität für kleine Hersteller ohne Compliance-Abteilung.
CRA fines and enforcement: what small companies actually risk
The EU Cyber Resilience Act carries fines up to €15 million or 2.5% of turnover — but that's the ceiling, not the likely outcome for a small manufacturer. How enforcement really works, what the tiers are, and where the sharper risk lies.
ENISA 24-hour reporting under the CRA: exact steps when a vulnerability is exploited
From 11 September 2026, manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours. What triggers the duty, the 24h/72h/final-report sequence, what each notification contains, and how to be ready before it happens.
CRA for machine builders: how it stacks on CE marking and the Machinery Regulation
Machine builders already know CE marking. The Cyber Resilience Act adds a cybersecurity layer on top: when your machine is in scope, how the CRA interacts with the Machinery Regulation, and what changes in your technical file.
CRA compliance for IoT startups: a practical guide
What the EU Cyber Resilience Act means for a small connected-hardware company: your risk class, the SBOM problem with firmware, the 24-hour reporting duty, and a realistic compliance plan for a team of five.
Does the EU Cyber Resilience Act apply to SaaS?
Pure cloud services are outside the CRA — but the exception is narrower than most software companies think. Where the line runs for SaaS, mobile apps, agents, on-prem software and remote data processing.
What is an SBOM — and how to create one without a DevOps team
A plain-language guide to Software Bills of Materials: what an SBOM is, why the EU Cyber Resilience Act requires one, the CycloneDX and SPDX formats, and how to generate one with free tools — even for firmware.
EU Cyber Resilience Act deadlines explained: 11 September 2026 vs 11 December 2027
The CRA has two deadlines that matter — the 24-hour reporting obligation from 11 September 2026 and full compliance by 11 December 2027. What applies when, to which products, and what to do first.
EU Cyber Resilience Act compliance checklist for small manufacturers (2026–2027)
A practical CRA checklist: what small hardware and software makers must have in place before 11 September 2026 and 11 December 2027 — SBOM, reporting, documentation, CE marking.