The CRA Technical Journal
An authoritative publication delivering 67 in-depth engineering memorandums, reference architectures, and statutory analyses with integrated audio podcasts across industrial OT, embedded IoT, and supply chain governance.
Curated Executive Briefings
The 2-Year Lag: Why 2024 Contracts Are Walking into a 2027 Regulatory Trap
Why turnkey infrastructure contracts signed with 2-year build phases result in non-compliant 2027 handover liabilities.
The Accidental Manufacturer: How System Integrators Trigger Article 21 Liability
When modifying custom PLC ladder logic or integrating multi-vendor skids legally reclassifies an EPC as the primary manufacturer.
The Edge-to-Cloud Grey Zone: When Microservices Void Local Controller CE Marks
Shattering the myth that OTA container pushes are purely IT operations. The unvarnished truth on CE mark voidance.
The €15M Calculation: Dissecting the Math Behind Article 64 Global Turnover Penalties
How European market surveillance authorities calculate the 2.5% global turnover fine and personal corporate officer liability.
The Port Surveillance Playbook: How Customs Inspects Software Bill of Materials
How European customs authorities intercept non-compliant embedded hardware at major European entry ports.
The 2-Year Lag: Why 2024 Contracts Are Walking into a 2027 Regulatory Trap
The CRA clock runs on the day a product is placed on the market, not the day you sign the PO. A 2024 specification with a 2028 delivery date is a compliance gap someone has to pay to close.
Writing the Bulletproof CRA RFP: Specification Language for Asset Owners
The Cyber Resilience Act binds your supplier, not you. Your RFP is the only place you get to control what actually shows up on the loading dock in 2027.
Variation Orders & Cost Shifts: Who Pays When CRA Forces a Mid-Project Redesign?
An OEM discontinues a legacy PLC mid-build and ships a CRA-compliant replacement with different power draw and footprint. A part-number swap becomes a redesign — and someone has to pay for it.
The Importer's Due Diligence Checklist: Buying Non-EU Hardware Legally
When a non-EU factory ships a product with digital elements into Rotterdam, the EU importer is the economic operator the market surveillance authority can actually reach. Here is exactly what you must verify before the container clears.
Distributor Gatekeeping: What Stock Must Be Purged Before December 2027?
The CRA does not scrap your warehouse on 11 December 2027. It grandfathers every unit already placed on the market — if you can prove the placing date. Here is how the rule actually works, and how to audit stock against it.
The Public Tender Playbook: Navigating EU Public Procurement Directives under CRA
You can require CRA conformity in a public tender without inviting an administrative-court appeal — but only if you separate the mandatory legal floor from the criteria you actually score.
The Accidental Manufacturer: How System Integrators Trigger 'Deemed Manufacturer' Liability
Five certified PLCs, a few thousand lines of custom SCADA Python, one configured edge gateway. You billed it as engineering hours. The CRA may read it as a product you manufactured — and own for a decade.
The 'Duty to Refrain': When Integrators Must Freeze Customer Deployments
You find an unpatched critical flaw in an OEM switch on the commissioning bench. Energising it and handing over the keys can make you the operator who placed a non-conforming product on the market. Here is where the duty actually lives and what to do with it.
Custom SCADA Scripts vs. Product Logic: Where the CRA Line Is Drawn
Bespoke ladder logic and one-off Ignition/WinCC dashboards feel like software products. The CRA's scope turns on three gates — and most site-specific plant code fails at least one of them.
The Multi-Plant Modernization Pipeline: A System Integrator's CRA Playbook
A repeatable retrofit pipeline that lets an integrator run overhauls across chemical, automotive, and energy plants while keeping the deemed-manufacturer line — Article 22 — on the right side.
Composite Systems & Brownfield Plant CE Marking: Who Owns the Nameplate?
Bolt certified pumps, drives, and controllers onto one skid and you have made a new product with digital elements. The component CE marks do not transfer — the technical file, the declaration, and the nameplate are now yours.
Drafting the Integrator Safe-Harbor Agreement: Contract Scaffolding for CRA Risk
A contract can move the cost of a CRA fine between you and your client. It cannot move who the authority calls the manufacturer. Here is how to draft for the difference.
The FAT/SAT Revolution: Adding Cybersecurity to Factory & Site Acceptance Testing
A loop test that passes every functional check can still ship with default passwords and an open debug port. Here is how to turn FAT and SAT into a CRA conformity gate.
The Spare-Parts Illusion: When a Replacement Part Is (and Isn't) Exempt
Plant teams treat every replacement part as outside the CRA. Article 2(6) exempts a much narrower thing — an identical component built to the same specification. Chip obsolescence quietly breaks both conditions.
When Maintenance Becomes Redesign: The Test for Brownfield Retrofits
Adding remote Ethernet diagnostics to a legacy 2005 packaging line—routine maintenance, or a substantial modification that reopens the machine's conformity?
Bridging the OEM Support Gap: Keeping 25-Year Assets Defensible after the CRA Clock Runs Out
The CRA makes a manufacturer support a product for at least five years. A distillation column runs for twenty-five. The years in between are the operator's problem to engineer, and NIS2 says so.
Streaming Legacy PLC Telemetry to the Cloud Without Pulling the Plant Into Scope
One worked integration — a pre-2027 S7-300 line to an edge broker to the cloud — and exactly where the CRA scope boundary falls.
The Obsolescence Stockpile: Smart Hedge or Uninsurable Trap?
Buying ten years of legacy modules before December 2027 can lock in grandfathered status — but only if you get one date right. A worked cost-and-risk breakdown of the stockpile decision.
Safety vs. Security: Patching Certified Equipment in Hazardous (ATEX) Areas
An emergency CRA security update lands for an explosion-proof transmitter in Zone 0. Applying it could breach the ATEX certificate that keeps the area safe. Two legal duties, one device — here is how to resolve it without picking a rule to break.
The Tier-2 Dilemma: Staying a Component Vendor Without an OEM-Sized Compliance Bill
Your OEM's six-figure audit demand is a contract term, not a CRA requirement. A component maker is a manufacturer only for its own component — and most default products self-assess. Where the law stops, the negotiation starts.
Generating an SBOM Tier-1 OEMs Will Accept: CycloneDX & SPDX for Embedded Firmware
The statute asks for one machine-readable file listing your top-level dependencies. Your Tier-1 buyer asks for far more. Both come off the same build — here is the artifact, field by field.
Vulnerability Data-Sharing Agreements: Feeding the OEM's Clock Without Leaking Your IP
When a flaw in your chip is actively exploited, your OEM customer has a 24-hour statutory clock — and it starts the moment they become aware. A data-sharing contract can decide what crosses the boundary and how fast. It cannot move the duty off the party the law names.
Open Source and the CRA: When a Maintainer Becomes a \
A pure community project sits outside the regulation. A \
White-Label & ODM Hardware: Whose Name on the Box, Whose Technical File
An Asian ODM builds hardware sold under an EU automation brand. Who is the legal manufacturer, and who must keep the technical file for at least 10 years?
The Component Supplier's Minimum Viable Security Kit: The 5 Documents That Pass a Tier-1 Audit
The absolute minimum documentation package that turns a small hardware vendor from a supply-chain liability into a preferred Tier-1 supplier — grounded in what Annex I and Article 13 actually require.
Data Centres & Facility Power: What the CRA Actually Reaches
Most of your power and cooling estate is a default product with digital elements that its maker self-assesses, not an Annex III important product. The class question is decided per product, and it usually bites in the network and security overlay, not the switchgear.
Smart Buildings: When Your BACnet Gateway Becomes a Regulated Product
Building-automation integrators treat a BACnet or Modbus gateway as infrastructure, not a product. The day it is placed on the EU market after the deadline, the Cyber Resilience Act says otherwise.
Patching the Grid: CRA Security Updates vs. Substation Stability
A protective relay on a live 400kV line is not a laptop you reboot on a whim. So when the Cyber Resilience Act meets a critical security update, who is actually obligated to do what, and when?
Water Utilities: Buying CRA-Ready RTUs for Remote Pumping Stations
A municipal water utility does not hold the CRA duty on a cellular RTU — the manufacturer does. Here is the procurement checklist that turns that duty into your evidence, and discharges your own NIS2 obligation.
Rail: Reconciling Multi-Year Safety Approvals with the CRA's Vulnerability Clock
A signalling safety case is authorised over years. The CRA's vulnerability-handling duty runs continuously. The reconciliation is architectural, not a waiver — decouple the safety-vital logic from the security-update layer so patches land where no authorisation lives.
Maritime & Ports: Where the CRA Stops and Marine-Equipment Law Begins
The Cyber Resilience Act carves out equipment covered by the Marine Equipment Directive (2014/90/EU). It does not carve out the quay crane. Here is the scope line for marine and port automation.
Patching Validated Pharma Systems: Security Updates Without a Full CSV Re-Run
A security patch to a validated batch reactor shouldn't cost you a six-month CSV re-run. The CRA's security baseline is risk-based, and so is modern validation. Here's how to scope the re-validation to the change.
Vehicle, Machine, or Product? Where the CRA Line Falls for AGVs and Off-Road Equipment
A type-approved road vehicle is out of the CRA and under UN R155. An off-road hauler, an AGV, a harvester is not a road vehicle — so it stays in the CRA and picks up the Machinery Regulation too. This is how to place the line.
The 24-Hour Early Warning: A Step-by-Step Playbook for the ENISA Notification
When a vulnerability in your product is actively exploited in the wild, the CRA gives you 24 hours to fire an early warning to the coordinating CSIRT and ENISA. Here is the hour-by-hour path from confirmation to submission — and the gate that keeps the clock from starting on a false alarm.
Building a Product Vulnerability-Handling Function That Meets Annex I
Your corporate SOC protects your email. A product vulnerability-handling function is a different org with a different job: keeping shipped products legal to sell. Here is how an industrial OEM stands one up from nothing.
Coordinated Disclosure: Turning a Researcher's Zero-Day Into a Managed Fix
A researcher drops proof-of-concept code for your industrial controller on GitHub with no warning. Under the CRA, how you answer is a compliance posture, not a public-relations decision.
The 72-Hour Notification: What Actually Goes in the Report
By hour 72 the early warning becomes a fuller filing. Here is the field-by-field breakdown of what the CRA requires, and what is just good incident-response practice you should add anyway.
Writing a Customer Security Advisory That Informs Without Arming
The CRA tells you which facts a security advisory must carry. It never tells you how to word them. That sentence-level judgement is the difference between getting operators patched and handing attackers a map.
Closing the Loop: The Final Report, the RCA, and the Technical-File Update
The crisis ends at the paperwork. After the patch ships, two duties survive it: the final report that closes your reporting obligation, and the technical-file update that has to hold up for a decade.
Self-Assessment vs. Notified Body: Which Conformity Route Your Product Actually Takes
Most products with digital elements can be assessed by the manufacturer alone, at zero external cost. A minority must pass through a notified body, and one class must go further still. This is the class-by-class map that tells you which route is yours before you price a single audit.
The Notified Body Bottleneck: Booking Audit Capacity Before the Crunch
The audit slots that can CE-mark a higher-risk product are scarce, slow to create, and all needed inside the same window before 11 December 2027. Treat notified-body capacity as a logistics problem: get in the queue early, with a dossier that won't bounce, and arrive already tested.
Drafting the EU Declaration of Conformity: The Annex V Field List and the Language Rules
The declaration is one page long and it is the document that carries your entire CRA liability. Annex V fixes eight fields; a missing standard reference or an untranslated copy can hold your product at the border. Here is the line-by-line.
The 10-Year Technical File: What Annex VII Requires and How to Archive It
A market-surveillance authority can ask for your technical documentation eight years after you shipped, and the file has to still exist, still be complete, and still be provably unaltered. This is the records job hiding inside the conformity job.
Presumption of Conformity: How Harmonised Standards Turn a Subjective Audit Into a Checklist
Annex I is written in outcomes, not instructions, which leaves an auditor to decide what 'appropriate security' means. A harmonised standard cited in the Official Journal does that translation once, for everyone, and flips the burden of proof. Here is how presumption works, and how to align development to the standards that will carry it before they are published.
CE Marking When the Board Is Smaller Than the Stamp: Physical, Digital & Packaging Rules
The CE mark is treated as the trivial last step before the pallet ships. It is a set of rules with real exceptions: where the mark goes on the product, what happens when the product is too small to carry it, how software is handled, and when a notified-body number belongs beside it. This is the affixing reference for people who design the enclosure.
The €15 Million Line: How Article 64 Administrative Fines Are Actually Calculated
The headline number is not €15 million. For any company of scale it is 2.5% of total worldwide group turnover — calculated on everything the undertaking sells everywhere, not on the revenue of the product that failed. This is how the three fine bands are built, and how to price your own exposure before an authority prices it for you.
Can a Director Go to Jail Over the CRA? Where Personal Liability Actually Comes From
The Cyber Resilience Act creates no personal criminal liability for directors. Its fines land on the company. The exposure that reaches the individual board member is written down somewhere else entirely, and confusing the two is how a risk committee mis-files its single largest governance question.
The Withdrawal Order: Responding When a Market Surveillance Authority Freezes Your Product
A market surveillance authority can evaluate your product, order corrective action, and — if you stall — pull it from the shelf itself, with the measure deemed justified across the Union three months later. The response is an operations problem. Pre-build the playbook before the notice lands, because the clocks start on their schedule, not yours.
One Industrial Machine, Three EU Laws: A Unified Evidence Map for CRA, NIS2 and the AI Act
A palletising robot on an essential-plant line sits inside three regulations at once: the CRA governs its firmware, the AI Act governs its vision model, NIS2 governs the plant that runs it. The programmes are separate, but the evidence overlaps in exactly three places and nowhere else. This is the map of where the work is done once and where it is not.
The Brussels Effect, Again: How the CRA Rewrites Global Industrial Product Design by 2030
A cookie banner in Ohio was never required by American law. It appeared because running one privacy regime for Europe and a weaker one for everyone else cost more than raising the global floor to Brussels' line. This is a forecast of the same mechanism playing out on physical products: why the cheapest way to satisfy the Cyber Resilience Act is to build every product line to its baseline, and what industrial design looks like on the other side of that decision.
The ENISA Single Reporting Platform Is Real, and the Clock Is Public
ENISA's Article 16 reporting platform is being stood up ahead of 11 September 2026 — the day the CRA's vulnerability and incident reporting duties start to bite, fifteen months before CE marking. Here is what is now in place and what the countdown actually asks of you.
The Real Mandate Is the Function, Not the Acronym: CRA Vulnerability Handling
Every vendor briefing says stand up a PSIRT before 2026. The Cyber Resilience Act never uses the word. Here is what Annex I Part II actually requires, and why the reporting clock makes it urgent now.
Your Customer's CRA Deadline Just Became Your Contract Term: What Component & Software Suppliers Must Deliver
The manufacturer who CE-marks the finished product owns your component's security. In 2027 that duty reaches you as a purchase-order clause. Here is what the CRA actually forces down the chain, and what is only leverage.
One Incident, Two Regulators: The CRA and NIS2 Reporting Clocks Are Not the Same Clock
A cyberattack on one industrial gateway can put a single company in front of two European regulators at once. The CRA clock and the NIS2 clock look identical and are not: different duty-holders, different triggers, different destinations. Filing under one does not discharge the other.
The Golden Ticket Isn't Printed Yet: Where the CRA Harmonised Standards Actually Stand
The Article 27 presumption of conformity is in force. The harmonised standards that make it usable are still being drafted under the CEN/CENELEC mandate and are not yet cited in the Official Journal. Here is what that gap means for a team planning its 2027 conformity, and what to build against while the shelf fills.
The Edge-to-Cloud Grey Zone: When a Microservice Update Reopens a Controller's CE Mark
A routine Tuesday deploy ships a new build to your controller's cloud backend. Nobody touched the hardware. Does the CE mark on the field cabinet still hold, or did the pipeline just reopen it?
The Defunct OEM Dilemma: Who Patches Brownfield OT When the Manufacturer Goes Bankrupt?
The Cyber Resilience Act puts the patching duty on the manufacturer. When the manufacturer is struck off, that duty has no one left to bind — and the risk quietly moves onto the operator under a different law.
Neural Weights on the Plant Floor: How the CRA and the AI Act Actually Divide an Autonomous Controller
A controller that runs a learned model sits inside two EU regulations at once. The Cyber Resilience Act asks whether the thing is secure and treats the weight file as an asset to protect. The AI Act asks whether the model is right and no security control ever answers that. Article 12 bridges exactly one of those questions. This is where the line actually falls.
The Open-Source Steward's Balance Sheet: What the CRA Actually Costs a Foundation
A steward's obligations are a fixed line of overhead, not a per-product bill. The expensive line is reserved for whoever sells a product — and a dual-license vendor quietly ends up on both.
Backdoor at the Border: How EU Market Surveillance Intercepts Firmware With Hidden Access
A container of networking gear can sit at a European port while a lab reads its firmware. A hardcoded credential is not an arguable defect; it is an Annex I failure on its face. When the manufacturer is offshore, the importer is the operator the Union can reach, so the real leverage is at the purchase order, not the port.
The End-of-Life Handover: Who Owns the CRA Liabilities When You Retire Critical OT?
Decommissioning feels like an off switch for compliance. It is not. The Cyber Resilience Act's clocks started the day the product was placed on the market and the day each update shipped, and unbolting the hardware does not stop them.
Where Does the 'Product' End? The CRA in Subsea and Space Mega-Systems
A bespoke subsea cable or a satellite constellation is not 'a product placed on the market.' The commercial modules inside it usually are. Here is how the Cyber Resilience Act draws the boundary through a mega-system, one line item at a time.
Battery Storage and the CRA: When a Cyber-Physical Fire Risk Meets Conformity Assessment
A compromised battery management system can drive good cells into thermal runaway — a security bug that ends as a fire. The real question is not whether the CRA covers your BESS, but which of its parts it puts through a notified body, and where its cybersecurity duties stop and functional safety begins.
Is Post-Quantum Crypto Now Mandatory? What the CRA Actually Says About 30-Year MCUs
A headline circulating in embedded circles says the Cyber Resilience Act now forces post-quantum cryptography into every microcontroller. The regulation names no algorithm anywhere. What it actually requires is a lifetime-aware risk assessment, and for a 30-year part that means crypto-agility, not a PQC mandate.
Secure Boot in an Explosive Atmosphere: When CRA Cybersecurity Collides With ATEX
A public exploit lands against the controller running your electrolyzer stack, and the CRA says the fix cannot wait. The controller sits in a Zone 1 enclosure under an ATEX certificate that treats its firmware as an unalterable part of the approved state. Both duties bind at once, and the reconciliation is an engineering problem, not a legal one.
When Machinery Safety Meets CRA Remote Control: The Autonomous Field Robot Problem
A spoofed steering command reaches a three-tonne autonomous harvester and it turns toward a field hand. Is that a machinery-safety failure or a product-cybersecurity failure? It is both, and the two regimes do not overlap by accident. The Machinery Regulation owns the safety function; the CRA owns the security posture. This is where the line actually falls, and the one place they land on the same wire.
The Underwriting Reckoning: How a CRA Failure Can Void Your Cyber and Tech E&O Cover
A cyber tower and a Tech E&O policy are supposed to be the backstop when a product breach turns into a loss. But the denial clause that empties them was written before the CRA existed, and the CRA now hands the insurer the documented standard it needs to enforce it. The same shipped defect draws a regulator, a claimant, and a coverage denial at once.
This Site Uses No Cookies
Eigenia does not set cookies. The only thing stored in your browser is one preference, saved in local storage, noting that you have seen this notice.