Nordchecks

Nordchecks

CRA Guides

Plain-language guides to the EU Cyber Resilience Act — scope, risk classes, deadlines, and what it takes to comply.

Gilt der CRA für Nicht-EU-Unternehmen?

Ja — der EU Cyber Resilience Act ist marktbasiert, nicht sitzbasiert. Wenn Sie ein Produkt mit digitalen Elementen in die EU verkaufen, gilt er, egal wo Ihr Unternehmen ansässig ist.

de8 min

Does the CRA apply to non-EU companies?

Yes — the EU Cyber Resilience Act is market-based, not establishment-based. If you sell a product with digital elements into the EU, it applies wherever your company is based.

8 min

The CRA in numbers: deadlines, fines and key figures

Every EU Cyber Resilience Act number that matters in one place — the phase-in dates, the 24/72-hour/14-day reporting windows, the fine tiers, the risk-class split and the support period, each with its source.

6 min

CRA Annex VII: the technical documentation, explained section by section

A plain-language walk through Annex VII of the EU Cyber Resilience Act: the eight elements your technical documentation must contain, what artifact satisfies each, and how the file connects to CE marking.

8 min

CRA for machine builders: your first SBOM without a dev team

A step-by-step first-SBOM walkthrough for machine builders with no software team: inventory the firmware, PLC/HMI and industrial PC, collect supplier SBOMs, and assemble a CycloneDX list by hand.

8 min

CRA compliance cost: what small manufacturers actually pay

An honest breakdown of CRA compliance cost for a small manufacturer — consultants and notified bodies vs a DIY open-source stack vs dedicated software — plus the real cost of non-compliance.

8 min

CRA-Compliance-Software: worauf Sie achten sollten

Eine Einkaufs-Checkliste für Cyber-Resilience-Act-Compliance-Software: die sechs Fähigkeiten, die wirklich zählen — SBOM, tägliches Monitoring, 24-Stunden-Meldung, Anhang-VII-Dokumente, Selbstbewertung und faire Preise.

de8 min

Cyber Resilience Act compliance software: what to look for

A buyer's checklist for cyber resilience act compliance software: the six capabilities that actually matter — SBOM, daily monitoring, 24h reporting, Annex VII docs, self-assessment and fair pricing.

8 min

CRA-Vorfallsmeldung: die Fristen von 24 Stunden, 72 Stunden und 14 Tagen

Die CRA-Meldepflicht läuft nach einer festen Uhr: Frühwarnung in 24 Stunden, Meldung in 72 Stunden, Abschlussbericht in 14 Tagen — Wochenenden inklusive. Wann die Uhr startet und an wen Sie melden.

de7 min

CRA incident reporting: the 24h / 72h / 14-day clock

The CRA reporting duty runs on a fixed clock — early warning in 24 hours, notification in 72 hours, final report in 14 days, weekends included. When the clock starts, what each stage contains, and who you report to.

7 min

What to do with a vulnerability finding: CRA triage explained

Your scanner flagged a CVE — now what? The CRA triage flow: assess severity and reachability, then decide fix-now, planned fix, not applicable, or accepted risk — and record every decision as the compliance artifact.

8 min

How to automate CRA compliance (instead of managing it in spreadsheets)

The EU Cyber Resilience Act means ongoing work: SBOMs per release, daily vulnerability monitoring, 24h reporting readiness and technical documentation. Here's how to automate it — and stop tracking it by hand.

7 min

CRA product classes explained: Default, Important (I & II) and Critical in plain English

The EU Cyber Resilience Act sorts products into risk classes that decide how you prove compliance — self-assessment or a notified body. Which class your product falls in, with plain examples, and why most products are Default.

7 min

CRA-Konformität: der praktische Leitfaden für kleine Hersteller

Was der EU Cyber Resilience Act von Ihnen verlangt — verständlich erklärt. Die Anforderungen, die zwei Fristen (11. September 2026 und 11. Dezember 2027) und ein realistischer Weg zur CRA-Konformität für kleine Hersteller ohne Compliance-Abteilung.

de9 min

CRA fines and enforcement: what small companies actually risk

The EU Cyber Resilience Act carries fines up to €15 million or 2.5% of turnover — but that's the ceiling, not the likely outcome for a small manufacturer. How enforcement really works, what the tiers are, and where the sharper risk lies.

7 min

ENISA 24-hour reporting under the CRA: exact steps when a vulnerability is exploited

From 11 September 2026, manufacturers must report actively exploited vulnerabilities to ENISA within 24 hours. What triggers the duty, the 24h/72h/final-report sequence, what each notification contains, and how to be ready before it happens.

8 min

CRA for machine builders: how it stacks on CE marking and the Machinery Regulation

Machine builders already know CE marking. The Cyber Resilience Act adds a cybersecurity layer on top: when your machine is in scope, how the CRA interacts with the Machinery Regulation, and what changes in your technical file.

8 min

CRA compliance for IoT startups: a practical guide

What the EU Cyber Resilience Act means for a small connected-hardware company: your risk class, the SBOM problem with firmware, the 24-hour reporting duty, and a realistic compliance plan for a team of five.

8 min

Does the EU Cyber Resilience Act apply to SaaS?

Pure cloud services are outside the CRA — but the exception is narrower than most software companies think. Where the line runs for SaaS, mobile apps, agents, on-prem software and remote data processing.

7 min

What is an SBOM — and how to create one without a DevOps team

A plain-language guide to Software Bills of Materials: what an SBOM is, why the EU Cyber Resilience Act requires one, the CycloneDX and SPDX formats, and how to generate one with free tools — even for firmware.

8 min

EU Cyber Resilience Act deadlines explained: 11 September 2026 vs 11 December 2027

The CRA has two deadlines that matter — the 24-hour reporting obligation from 11 September 2026 and full compliance by 11 December 2027. What applies when, to which products, and what to do first.

7 min

EU Cyber Resilience Act compliance checklist for small manufacturers (2026–2027)

A practical CRA checklist: what small hardware and software makers must have in place before 11 September 2026 and 11 December 2027 — SBOM, reporting, documentation, CE marking.

9 min