Notes
Plain-language notes on the Cyber Resilience Act, for small device makers. Each note cites the article it explains.

The email nobody read for a day: a CRA lesson from the Medicare incident
A security report sat in a public inbox that was checked once a day. What the Medicare portal incident teaches device makers about the CRA's 24-hour clock.
Read the note
We only make a module. Is the OEM responsible under the CRA?
Sell a module under your own name? The EU Cyber Resilience Act then treats you as a manufacturer, with your own reporting duty. Plain words, exact articles.
Read the note