AA-sec Resources

Practical guidance for secure, CRA-ready products.

Articles, guides, and technical resources for product teams building continuous security and traceable evidence.

Latest

Recent resources

Section

Cyber Resilience Act

Practical guidance on CRA scope, obligations, timelines, and product readiness.

All sections ↑
22 August 2026Cyber Resilience Act harmonised standards 2026 · Cyber Resilience Act harmonised standards · CRA M/606 standards

CRA Harmonised Standards in 2026: What Manufacturers Should Track

A practical guide to CRA harmonised standards in 2026, covering M/606 deliverables, Official Journal citation, presumption of conformity, and what manufacturers should track.

19 August 2026Cyber Resilience Act conformity assessment paths · CRA conformity assessment · CRA self assessment

CRA Conformity Assessment Paths by Product Class

A practical guide to choosing the CRA conformity assessment route for default, Class I, Class II and critical products, including Modules A, B+C and H.

17 August 2026Cyber Resilience Act product classification · CRA product classification · CRA important products Class I

CRA Product Classification: Default, Class I, Class II and Critical

A practical guide to CRA product classification: how core functionality separates the default category from important Class I, Class II and critical products.

14 August 2026Cyber Resilience Act substantial modification · Cyber Resilience Act substantial modification · CRA modified product obligations

CRA Substantial Modification: When Changes Trigger New Duties

A practical guide to CRA substantial modification, including software updates, repairs, risk changes, manufacturer obligations, conformity assessment, and release evidence.

13 August 2026Cyber Resilience Act support period requirements · Cyber Resilience Act support period · CRA five year support period

CRA Support Period Requirements and the Five-Year Rule

A practical guide to CRA support period requirements, including the five-year minimum, longer-lived products, shorter-use exceptions, documentation, and update retention.

9 August 2026Cyber Resilience Act products with digital elements · Cyber Resilience Act scope · products covered by CRA

Which Products with Digital Elements Are in Scope of the CRA?

A practical guide to deciding whether hardware, software, components and manufacturer-controlled remote processing fall within the Cyber Resilience Act, including common exclusions.

Section

SBOM

Software bill of materials practices for product visibility and vulnerability response.

All sections ↑
22 August 2026release-specific SBOM quality · SBOM completeness · SBOM accuracy

SBOM Quality: Completeness, Accuracy, and Release Traceability

A practical guide to improving SBOM quality through explicit completeness, reliable component identity, dependency accuracy, release binding, validation, and retained evidence.

11 August 2026Cyber Resilience Act SBOM requirements · Cyber Resilience Act SBOM · CRA software bill of materials

SBOM Requirements Under the Cyber Resilience Act

A practical guide to CRA SBOM requirements, including minimum dependency coverage, machine-readable format, technical documentation, disclosure boundaries, and lifecycle maintenance.

Section

Vulnerability Management

Repeatable vulnerability intake, assessment, remediation, and disclosure workflows.

All sections ↑
23 August 2026VEX for CRA vulnerability impact decisions · VEX Cyber Resilience Act · VEX SBOM vulnerability status

How VEX Supports CRA Vulnerability Impact Decisions

A practical guide to using VEX for product-specific vulnerability impact decisions, with scoped status, supporting rationale, release traceability, and retained evidence for CRA readiness.

13 August 2026Cyber Resilience Act severe incident definition · Cyber Resilience Act severe incident · CRA incident severity criteria

CRA Severe Incident: Definition and Reporting Trigger

A practical explanation of the CRA severe-incident threshold, the two Article 14 severity tests, reporting deadlines, user communication, and evidence to retain.

13 August 2026Cyber Resilience Act vulnerability handling process · CRA vulnerability handling process · Cyber Resilience Act vulnerability management

How to Build a CRA Vulnerability Handling Process

A practical guide to building a CRA vulnerability handling process that connects intake, triage, remediation, disclosure, updates, component coordination, and evidence.

12 August 2026Cyber Resilience Act security update requirements · Cyber Resilience Act security updates · CRA free security updates

CRA Security Update Requirements for Manufacturers

A practical guide to CRA security update requirements, covering remediation, secure distribution, automatic updates, user notices, availability, and release evidence.

8 August 2026actively exploited vulnerability under the CRA · CRA actively exploited vulnerability · actively exploited vulnerability definition

What Counts as an Actively Exploited Vulnerability Under the CRA?

A practical guide to the CRA definition of an actively exploited vulnerability, the reliable-evidence threshold, awareness timing, and defensible triage records.

7 August 2026CRA Single Reporting Platform preparation · ENISA CRA reporting platform · CRA SRP readiness

How to Prepare for the CRA Single Reporting Platform

A practical preparation guide for the CRA Single Reporting Platform, covering EU Login, assigned representatives, reporting data, evidence, and internal workflow.

6 August 2026Cyber Resilience Act vulnerability reporting requirements · CRA vulnerability reporting requirements · CRA Article 14 reporting

CRA Vulnerability Reporting Requirements for Manufacturers

A practical explanation of CRA reporting duties for actively exploited vulnerabilities and severe incidents, including deadlines, routing, evidence, and preparation.

Section

Security Evidence

Traceable evidence that supports product security decisions and compliance work.

All sections ↑
16 August 2026CRA product security evidence checklist · CRA evidence checklist · product security compliance evidence

Product Security Evidence Checklist for CRA Readiness

A practical CRA readiness checklist for product-security evidence, covering scope, risk assessment, SBOM, testing, vulnerability decisions, releases, user information and retention.

15 August 2026Cyber Resilience Act technical documentation · CRA technical documentation requirements · CRA Annex VII documentation

CRA Technical Documentation: What Manufacturers Need to Retain

A practical guide to CRA technical documentation, covering Annex VII evidence, risk assessment, vulnerability handling, test reports, retention and lifecycle updates.

Section

Product Security

Security engineering practices across product design, development, release, and maintenance.

All sections ↑
24 August 2026CRA known exploitable vulnerability release gate · Cyber Resilience Act known exploitable vulnerabilities · CRA release vulnerability gate

Known Exploitable Vulnerabilities Under the CRA: Release Gate Evidence

A practical guide to deciding whether a known exploitable vulnerability blocks CRA market placement, with product-specific triage, release-gate evidence, and documented decisions.

21 August 2026Cyber Resilience Act third-party component due diligence · CRA third party component due diligence · Cyber Resilience Act third party components

CRA Third-Party Component Due Diligence: What Manufacturers Need to Evidence

A practical guide to CRA third-party component due diligence, covering component selection, integration risk, vulnerability handling, support signals, and retained evidence.

20 August 2026ENISA SME Cyber Resilience Maturity Assessment · ENISA CRA maturity assessment · CRA maturity assessment SMEs

How to Use ENISA's SME CRA Maturity Assessment

A practical guide to using ENISA's SME cyber-resilience maturity model to identify product-security gaps, prioritise improvements, and avoid treating a maturity score as proof of CRA compliance.

18 August 2026Cyber Resilience Act secure by design and default · CRA secure by design and default · Cyber Resilience Act secure by default

CRA Secure by Design and Default: Practical Engineering Guide

A practical guide to translating CRA secure-by-design and secure-by-default requirements into engineering actions, release evidence, and repeatable product-security checks.

10 August 2026Cyber Resilience Act cybersecurity risk assessment · CRA cybersecurity risk assessment · Cyber Resilience Act risk assessment

How to Perform a CRA Cybersecurity Risk Assessment

A practical guide to CRA cybersecurity risk assessment, covering product scope, intended and foreseeable use, threats, Annex I mapping, evidence, and reassessment triggers.