EITC/IS/CRA authoritative open-access reference resources — complete six-lesson programme
Regulation (EU) 2024/2847 and applicable published delegated or implementing acts are the controlling legal sources. Official guidance, standards and professional frameworks support interpretation and implementation but do not replace product-specific legal, technical, reporting and conformity decisions. Harmonised standards create a presumption of conformity only after their references are published in the Official Journal and only for the requirements and scope covered. Source status should be rechecked after the programme baseline of 23 June 2026.
Core Cyber Resilience Act sources and implementation status
- Regulation (EU) 2024/2847 — Cyber Resilience Act
- Implementing Regulation (EU) 2025/2392 — technical descriptions of important and critical products
- Delegated Regulation (EU) 2026/881 — conditions for delaying dissemination of certain Article 14 notifications
- European Commission — Cyber Resilience Act overview
- European Commission — CRA implementation tracker
- European Commission — CRA implementation frequently asked questions
- European Commission — CRA obligations for manufacturers
Lesson 1 — scope, roles, classification and governance
- European Commission — CRA summary and essential cybersecurity requirements
- European Commission — Blue Guide 2022 on EU product rules
- Directive (EU) 2022/2555 — NIS2
- Regulation (EU) 2016/679 — GDPR
- Regulation (EU) 2022/2554 — DORA
Lesson 2 — secure-by-design engineering and verification
- NIST SP 800-218 — Secure Software Development Framework
- OWASP — Threat Modeling Cheat Sheet
- OWASP ASVS — application-security requirements and verification
- ETSI EN 303 645 — consumer IoT cybersecurity baseline
Lesson 3 — lifecycle, supply chain, SBOM and secure updates
- ENISA — SBOM Adoption State of Play 2026
- ENISA — Technical Advisory for Secure Use of Package Managers
- NIST SP 800-161 Rev. 1 — Cybersecurity Supply Chain Risk Management
- SPDX — software bill of materials specification and resources
- CycloneDX — SBOM and security transparency specification
- SLSA specification 1.2 — build and provenance assurance
- in-toto — software supply-chain attestations
- Sigstore/cosign — artifact signing and verification
- The Update Framework — compromise-resilient update design
Lesson 4 — vulnerability handling, reporting and field assurance
- European Commission — CRA reporting obligations
- ENISA — CRA Single Reporting Platform information
- ENISA — coordinated vulnerability disclosure resources
- RFC 9116 — security.txt
- FIRST — PSIRT Services Framework 1.1
- FIRST — Common Vulnerability Scoring System
- FIRST — Exploit Prediction Scoring System
- CISA — Known Exploited Vulnerabilities Catalog
- OASIS CSAF 2.1 — Common Security Advisory Framework
- NIST SP 800-61 Rev. 3 — incident response
Lesson 5 — standards, conformity, documentation and market assurance
- European Commission — CRA conformity assessment
- European Commission — CRA harmonised standards and standardisation request
- European Commission — NANDO notified-body information system
- ENISA — technical competence requirements for CRA notified bodies
- ENISA/JRC — CRA requirements and standards mapping
- Regulation (EU) 2019/1020 — market surveillance and compliance of products
- European Commission — market surveillance
Lesson 6 — continuous assurance, secure change, automation and AI-enabled products
- European Commission — 2026 draft CRA guidance consultation notice
- NIST OSCAL — machine-readable control and assessment information
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- European Commission — AI Act regulatory framework
- NIST AI Risk Management Framework
- NIST AI RMF Generative AI Profile
- OWASP GenAI Security Project — LLM Top 10
- ENISA — Cybersecurity Exercise Methodology
These references support learning and implementation. No individual framework, score, certificate, tool, data format or automated result is sufficient by itself to establish CRA applicability, conformity, reportability or acceptable residual risk.

