Cyber Resilience Act
CRA guidance, official and practical
A single place to find CRA guidance. The official Commission and ENISA sources, the working guides for each compliance task, and tailored guidance for your role, industry, and country.
Official guidance
Start with the primary sources. The regulation text, the Commission's own guidance, and the ENISA infrastructure that underpins reporting.
The CRA regulation, article by article
Every article and annex of Regulation (EU) 2024/2847 explained in plain language.
Every worked example in the Commission's guidance
All 67 numbered examples and 5 remote data processing use cases from C(2026) 5252 final, reproduced word for word.
What the adopted Commission guidance settles
The Article 26 guidance adopted on 27 July 2026, and what changed from the consultation draft.
ENISA, the EUVD and Article 14
The Single Reporting Platform, the European Vulnerability Database, and national CSIRTs.
Guidance by task
Working guides for the jobs a manufacturer actually has to do to comply.
How CRA compliance works
The end-to-end path from classification to CE marking.
CRA compliance checklist
A step-by-step checklist covering the core obligations.
CRA reporting obligations
The 24-hour and 72-hour reporting duties and who they apply to.
Article 14 reporting
Reporting actively exploited vulnerabilities and severe incidents.
Product classifier
Work out whether a product is default, important Class I or II, or critical.
Guidance by role, industry and country
Tailored guidance for who you are, what you build, and where you sell.
Standards guidance
How the CRA maps to the standards manufacturers use to demonstrate conformity.
Turn guidance into an audit-ready file
Work through the CRA obligations in one workspace and export an Annex VII technical file.
Get Started for Free