CRA Support
Cyber Resilience Act for Embedded Systems
While working through the CRA (EU) 2024/2847, we created a graphic "EU Cyber Resilience Act Architecture" to better understand it, which gradually mapped out all organizations and relationships (AI was overwhelmed with this – if you want it done right, do it yourself).
Since the graphic has been very helpful to us, we decided to publish it under the GPL to make it easier for companies to understand the CRA.
If you need help with the CRA or its implementation, we are happy to assist you.
Valuable Links
For independent study and in-depth information, we recommend the official sources of the European Union and the Federal Office for Information Security (BSI):
-
The Original Statutory Text of the CRA:
The complete Regulation (EU) 2024/2847 in the legal portal of the European Union
EUR-Lex – Regulation (EU) 2024/2847 (Cyber Resilience Act) -
Official Topic Page of the BSI:
Current FAQs, timelines, and German guidance for companies
BSI – Topic Focus Cyber Resilience Act -
EU Guidelines & Funding Programs for SMEs:
The official overview page of the EU Commission with specific resources, simplified forms, and EU funding projects (such as SECURE, CONFIRMATE, OCCTET) for small and medium-sized enterprises:
EU Commission – CRA Portal for Micro-Enterprises and SMEs
-
Practical Handbook of ENISA (Secure by Design Playbook):
The official handbook of the European Union Agency for Cybersecurity (ENISA), which translates the CRA requirements into concrete technical checklists for product developers:
ENISA – Publications & SME Guides -
OpenSSF Guide for Open Source Developers:
The Open Source Security Foundation breaks down plainly what exact duties and exceptions apply to software stewards and maintainers under the CRA.
OpenSSF – EU Cyber Resilience Act Resource Guide -
CRA Practical Guide for Device Manufacturers (GitHub)
An excellent, open step-by-step guide from the field that provides manufacturers of connected devices and IoT hardware with concrete checklists for classification and risk analysis.
GitHub – CRA Practical Guide by balena-io -
The Collaborative CRA FAQ:
An extremely detailed FAQ catalog run by the Open Regulatory Compliance Working Group that clearly resolves ambiguities in the statutory text for developers.
CRA FAQ – Open Regulatory Compliance WG