GUIDES
Reference guides for CRA readiness and system safety.
Working references on the Cyber Resilience Act and the safety and security standards it sits alongside, written for engineers and programme owners who need the substance rather than a summary.
- CRAWhat the Cyber Resilience Act requires of manufacturersThe CRA is not a single checklist; it is a set of interlocking obligations that touch design, documentation, operations and the supply chain.
- CRACRA timeline and deadlinesThree dates matter in practice; everything else is detail that hangs off them.
- CRAConformity assessment routes under the CRAConformity assessment is not a single procedure; the route depends entirely on how a product is classified.
- CRACRA technical documentationTechnical documentation is the artefact reviewers actually read; its structure determines whether an assessment is fast or slow.
- CRASBOM and coordinated vulnerability handlingAn SBOM is only useful if it can answer a question quickly; a vulnerability handling process is only credible if it has been exercised.
- Functional safetyISO 26262 functional safetyISO 26262 succeeds or fails on whether ASIL decomposition and traceability hold together end to end, not on whether a document set exists.
- Functional safetyIEC 61508 functional safety basicsMost IEC 61508 programmes stall on the same three questions: which SIL level is actually justified, how the safety lifecycle fits a real delivery plan, and what evidence assessors expect. This guide answers them directly.
- Product securityIEC 62443 product securityIEC 62443 is a family of standards addressing different roles in the industrial automation supply chain, and confusing the roles is the most common source of misapplied requirements.
- Product securityISO/SAE 21434 automotive cybersecurityAutomotive cybersecurity work fails in predictable places: a TARA done once and never revisited, feasibility ratings nobody can defend, and a UN R155 audit that asks for organisational evidence the project never produced. This guide covers the method and those gaps.
- Product securityAutomotive cybersecurity: standards, regulation and engineering practiceThis is the entry point to the automotive cybersecurity cluster: which instrument applies to what, how the risk method works, what an audit asks for, and where programmes typically lose time.
- Product securityThe cybersecurity management system (CSMS)Most first-time UN R155 audits are not lost on technical analysis. They are lost on organisational evidence that the project never produced because nobody owned it.
- System safetySafety cases and evidence chainsA safety case is an argument, not a folder of documents; the argument is only as strong as its weakest link.
- CRAThe CRA for small manufacturers and SMEsSize does not remove obligations, but it does change how a compliance programme should be sequenced when a handful of engineers own the whole product.
- Product securityThreat modelling for connected productsA threat model earns its cost when it changes the architecture. If it only produces a report, it was documentation, not engineering.
- Product securityBuilding a secure development lifecycle that holds up as evidenceThe CRA does not ask whether you care about security. It asks you to show the process that produced the product, and the records it left behind.