
How to Evaluate CRA Compliance Software Beyond Checklists
A practical framework for evaluating CRA compliance software by lifecycle traceability, risk assessment, SBOM, vulnerability evidence, audit history and workflow fit.
Read article
AA-sec
Articles, guides, and technical resources for product teams building continuous security and traceable evidence.

A practical framework for evaluating CRA compliance software by lifecycle traceability, risk assessment, SBOM, vulnerability evidence, audit history and workflow fit.
Read article
The CRA allows unfinished alpha, beta and release-candidate software to be offered for testing under specific conditions. Learn what controls and evidence manufacturers should retain.
Read article
The CRA does not give all open-source software a blanket exemption. Learn how commercial activity, responsibility and the steward role change the legal analysis.
Read article
CycloneDX and SPDX can both support CRA SBOM workflows. Compare their data models, lifecycle fit, tooling and interoperability before choosing a release format.
Read article
A practical guide for manufacturers building a CRA coordinated vulnerability disclosure policy, covering contact channels, intake, triage, researcher coordination, remediation, publication and evidence.
Read article
A practical manufacturer checklist for CRA Annex II user information, covering product identity, vulnerability contacts, support dates, secure-use instructions and release evidence.
Read articlePractical guidance on CRA scope, obligations, timelines, and product readiness.
The CRA does not give all open-source software a blanket exemption. Learn how commercial activity, responsibility and the steward role change the legal analysis.
A practical guide to CRA harmonised standards in 2026, covering M/606 deliverables, Official Journal citation, presumption of conformity, and what manufacturers should track.
A practical guide to choosing the CRA conformity assessment route for default, Class I, Class II and critical products, including Modules A, B+C and H.
A practical guide to CRA product classification: how core functionality separates the default category from important Class I, Class II and critical products.
A practical guide to CRA substantial modification, including software updates, repairs, risk changes, manufacturer obligations, conformity assessment, and release evidence.
A practical guide to CRA support period requirements, including the five-year minimum, longer-lived products, shorter-use exceptions, documentation, and update retention.
A practical guide to deciding whether hardware, software, components and manufacturer-controlled remote processing fall within the Cyber Resilience Act, including common exclusions.
A practical starting point for Cyber Resilience Act readiness, covering product scope, risk assessment, vulnerability handling, evidence, and reporting preparation.
Software bill of materials practices for product visibility and vulnerability response.
CycloneDX and SPDX can both support CRA SBOM workflows. Compare their data models, lifecycle fit, tooling and interoperability before choosing a release format.
A practical CI/CD workflow for generating release-specific SBOMs, validating the result, binding it to the shipped artifact, and retaining evidence for later vulnerability work.
A practical guide to improving SBOM quality through explicit completeness, reliable component identity, dependency accuracy, release binding, validation, and retained evidence.
A practical guide to CRA SBOM requirements, including minimum dependency coverage, machine-readable format, technical documentation, disclosure boundaries, and lifecycle maintenance.
Repeatable vulnerability intake, assessment, remediation, and disclosure workflows.
A practical guide for manufacturers building a CRA coordinated vulnerability disclosure policy, covering contact channels, intake, triage, researcher coordination, remediation, publication and evidence.
A practical guide to using VEX for product-specific vulnerability impact decisions, with scoped status, supporting rationale, release traceability, and retained evidence for CRA readiness.
A practical explanation of the CRA severe-incident threshold, the two Article 14 severity tests, reporting deadlines, user communication, and evidence to retain.
A practical guide to building a CRA vulnerability handling process that connects intake, triage, remediation, disclosure, updates, component coordination, and evidence.
A practical guide to CRA security update requirements, covering remediation, secure distribution, automatic updates, user notices, availability, and release evidence.
A practical guide to the CRA definition of an actively exploited vulnerability, the reliable-evidence threshold, awareness timing, and defensible triage records.
A practical preparation guide for the CRA Single Reporting Platform, covering EU Login, assigned representatives, reporting data, evidence, and internal workflow.
A practical explanation of CRA reporting duties for actively exploited vulnerabilities and severe incidents, including deadlines, routing, evidence, and preparation.
Traceable evidence that supports product security decisions and compliance work.
A practical manufacturer checklist for CRA Annex II user information, covering product identity, vulnerability contacts, support dates, secure-use instructions and release evidence.
A practical CRA readiness checklist for product-security evidence, covering scope, risk assessment, SBOM, testing, vulnerability decisions, releases, user information and retention.
A practical guide to CRA technical documentation, covering Annex VII evidence, risk assessment, vulnerability handling, test reports, retention and lifecycle updates.
Security engineering practices across product design, development, release, and maintenance.
The CRA allows unfinished alpha, beta and release-candidate software to be offered for testing under specific conditions. Learn what controls and evidence manufacturers should retain.
A practical guide to designing effective and regular CRA security testing, selecting test depth by risk, and retaining evidence that supports product and vulnerability-handling decisions.
A practical guide to deciding whether a known exploitable vulnerability blocks CRA market placement, with product-specific triage, release-gate evidence, and documented decisions.
A practical guide to CRA third-party component due diligence, covering component selection, integration risk, vulnerability handling, support signals, and retained evidence.
A practical guide to using ENISA's SME cyber-resilience maturity model to identify product-security gaps, prioritise improvements, and avoid treating a maturity score as proof of CRA compliance.
A practical guide to translating CRA secure-by-design and secure-by-default requirements into engineering actions, release evidence, and repeatable product-security checks.
A practical guide to CRA cybersecurity risk assessment, covering product scope, intended and foreseeable use, threats, Annex I mapping, evidence, and reassessment triggers.
Product updates and practical workflows supported by the AA-sec platform.
A practical framework for evaluating CRA compliance software by lifecycle traceability, risk assessment, SBOM, vulnerability evidence, audit history and workflow fit.