CRA Support

Cyber Resilience Act for Embedded Systems

While working through the CRA (EU) 2024/2847, we created a graphic "EU Cyber Resilience Act Architecture" to better understand it, which gradually mapped out all organizations and relationships (AI was overwhelmed with this – if you want it done right, do it yourself).

Since the graphic has been very helpful to us, we decided to publish it under the GPL to make it easier for companies to understand the CRA.

If you need help with the CRA or its implementation, we are happy to assist you.

Valuable Links

For independent study and in-depth information, we recommend the official sources of the European Union and the Federal Office for Information Security (BSI):

  • Practical Handbook of ENISA (Secure by Design Playbook):
    The official handbook of the European Union Agency for Cybersecurity (ENISA), which translates the CRA requirements into concrete technical checklists for product developers:
    ENISA – Publications & SME Guides

  • OpenSSF Guide for Open Source Developers:
    The Open Source Security Foundation breaks down plainly what exact duties and exceptions apply to software stewards and maintainers under the CRA.
    OpenSSF – EU Cyber Resilience Act Resource Guide

  • CRA Practical Guide for Device Manufacturers (GitHub)
    An excellent, open step-by-step guide from the field that provides manufacturers of connected devices and IoT hardware with concrete checklists for classification and risk analysis.
    GitHub – CRA Practical Guide by balena-io

  • The Collaborative CRA FAQ:
    An extremely detailed FAQ catalog run by the Open Regulatory Compliance Working Group that clearly resolves ambiguities in the statutory text for developers.
    CRA FAQ – Open Regulatory Compliance WG