Resources
Practical templates, whitepapers and CRA briefings for implementing cybersecurity requirements – free to download.
- All Resources
- Templates
- Whitepapers
- Briefings
SBOM Template
2025Structured template for listing every software component the CRA requires you to track. Includes work instructions for development teams and examples.
Risk Assessment
2025Template for risk assessment under the new Machinery Regulation according to EN 50742.
CRA Reporting Process
2025Process descriptions and templates for reporting obligations under the Cyber Resilience Act.
The Case for a PSO
2025Whitepaper on why a Product Security Officer should be responsible for product security.
The Path to CRA Conformity
2026Between knowing the CRA applies to you and the CE marking lie three phases and twelve steps. The briefing shows the scope and sequence of each task, plus the three planning principles: build the processes once and scale them across products, work backward from 12/2027, run tasks in parallel rather than in sequence.
CRA Reporting Obligations under Art. 14
2026Not every vulnerability triggers a report, but when it counts you have 24 hours. The briefing separates vulnerability management from the reporting duty, names what triggers a report under Art. 14, the deadlines that start the moment you know, and who has to be informed – plus what has to be ready before 11 September 2026.
SBOM and Component Management
2026The SBOM is seen as the big hurdle in the CRA, but creating it is not the hard part. The briefing shows what the CRA actually requires of a software bill of materials and what it does not, why the work sits in component management before integration, what scanners reliably detect, and who gets to see the SBOM at all.
From EN 18031 to EN 40000-1-4
2026Your EN 18031 evidence is valuable, but it is not enough for the CRA. The CRA's technical requirements come from EN 40000-1-4, currently still at draft stage. The briefing shows what carries over and what does not: revised controls behind unchanged IDs, at least 29 new controls, the question of a vertical product standard, and a structured way through the delta.
From RED and EN 18031 to the CRA
2026RED was the rehearsal, the CRA is the real deal. What you proved on the device under RED are product properties; the CRA demands end-to-end processes across the lifecycle: a secure development lifecycle, vulnerability management with CVD, an SBOM, 24-hour reporting for actively exploited vulnerabilities, free security updates for at least five years. The briefing shows what your RED evidence cannot deliver – and why enforcement will be active this time.
Implementing the Machinery Regulation and the CRA Together
2026A connected machine placed on the market from 2027 falls under the Machinery Regulation and the CRA at the same time – neither framework exempts the other. Start two separate projects and you pay twice. The briefing shows the four dates that set the pace, how risk assessment and technical documentation can run on a shared foundation, why conformity assessment stays a separate procedure per regulation, and where the CRA stands alone.
ISO 27001 and the CRA
2026An ISMS certificate does not earn a product its CE marking. The briefing sets the two frameworks side by side on scope, evidence and penalties, and names which parts of your ISMS you can reuse for the CRA and which product-level duties you still have to cover.
Get in Touch
Ready for the Next Step?
Want to know which cybersecurity requirements apply to your products, and what it takes to meet them in engineering and in your processes? In a short call we go through your product and lay out the next steps.
Schedule a Call
Fill out the form. We'll get back to you promptly to arrange a consultation.