Reference
Topics
Cross-cutting reading paths through the Regulation, its annexes and official guidance.
| Article 14 reporting, end to end | The live obligation: triggers, clocks, platform, and user notification. |
| CE marking for software | What the mark means, who affixes it, and how software carries it. |
| Conformity assessment | Modules, routes, and choosing the cheapest honest path. |
| Coordinated vulnerability disclosure | The CVD policy duty and the single point of contact. |
| Cybersecurity risk assessment | The document Annex I keeps pointing back to. |
| Declaration of Conformity | The document where the manufacturer signs its own homework. |
| Harmonised standards | The missing piece that decides how easy self-assessment will be. |
| Important and critical products | The classification layer: what the lists change and how to read them. |
| Market surveillance | Who enforces the Regulation, and with what. |
| Notified bodies | The third-party assessment infrastructure, still being built out. |
| Open source under the CRA | Where the manufacturer track ends and the steward regime begins. |
| Product lifecycle | The Regulation as a timeline: design, ship, support, retire. |
| Products already on the market | What the 2027 line actually grandfathers, and what it does not. |
| Remote data processing | The clause that pulls backends into a product Regulation. |
| The SBOM requirement | What the software bill of materials duty actually asks for. |
| Scope framework | How Article 2 decides what the Regulation touches at all. |
| Secure by design and default | The Part I properties, and the configuration duty behind the slogan. |
| Security updates | Free, timely, and — for consumer products — installed automatically by default. |
| The single reporting platform | One submission, correctly routed: how the ENISA platform fits Article 14. |
| Substantial modification | The post-market change that brings conformity duties into play, and how to assess it. |
| The support period | A five-year floor, with exceptions, and what runs during it. |
| Technical documentation | The audit binder: what goes in it and how to build it without pain. |
| User notification | Telling users, separately from telling authorities. |
| Vulnerability handling | The Part II process duties, translated into an operating rhythm. |