Book a call

Notes

Plain-language notes on the Cyber Resilience Act, for small device makers. Each note cites the article it explains.

  1. 7 min read

    The email nobody read for a day: a CRA lesson from the Medicare incident

    A security report sat in a public inbox that was checked once a day. What the Medicare portal incident teaches device makers about the CRA's 24-hour clock.

    Read the note
  2. 6 min read

    We only make a module. Is the OEM responsible under the CRA?

    Sell a module under your own name? The EU Cyber Resilience Act then treats you as a manufacturer, with your own reporting duty. Plain words, exact articles.

    Read the note