Blog

Blog

Insights, guides, and updates about EU Cyber Resilience Act compliance and manufacturing cybersecurity.

CRA Compliance Knowledge for Manufacturers

The EU Cyber Resilience Act (CRA) sets new cybersecurity standards for all products with digital elements — from IoT devices and industrial machinery to embedded systems and smart home products. Our blog provides practical guides, expert analysis, and timely updates to help manufacturers, OEMs, and Tier-1 suppliers navigate the path to CRA compliance. Whether you need to understand SBOM management, vulnerability monitoring, ENISA incident reporting, or the CRA timeline with its key deadlines in September 2026 and December 2027 — you'll find actionable insights here.

Topics We Cover

  • SBOM Management & Software Composition Analysis
  • Vulnerability Monitoring & Patch Management
  • CRA Timeline, Deadlines & Penalties
  • Security by Design for Connected Products
  • Industry-Specific Compliance Strategies
  • ENISA Reporting & Audit Documentation
SoftwareIoTEmbedded Systems

CRA Friday Facts: Beta Releases Are Not Banned, They Are Regulated

Can you still ship beta software under the CRA? Yes, Article 19 allows it under two clear conditions. What manufacturers need to know.

June 26, 2026
8 min read
Maximilian Heck
Read more
CRA vs PLDProduct Liability DirectiveCyber Resilience Act

CRA vs Product Liability Directive: How the Two EU Laws Interact for Software Manufacturers

The EU Cyber Resilience Act and the revised Product Liability Directive (PLD) both target software-bearing products — but with very different mechanisms. Here is what manufacturers need to know about the overlap.

June 21, 2026
6 min read
Waldemar Kindler
Read more
Industrial MachineryCRA ComplianceCyber Resilience Act

EU CRA Compliance for Machinery: A Step-by-Step Guide for Industrial OEMs

A practical, step-by-step guide for industrial machinery OEMs to achieve EU Cyber Resilience Act compliance — from product inventory to notified body engagement and ongoing SBOM management.

June 21, 2026
7 min read
Waldemar Kindler
Read more
Multi-ProductPlatform StrategyCRA Compliance

EU CRA Compliance Across Multiple Product Variants: A Platform Strategy for Manufacturers

When your portfolio has 50, 100, or 500 product variants, EU CRA compliance breaks every spreadsheet. Here is the platform strategy that keeps multi-product manufacturers compliant without exponential overhead.

June 21, 2026
6 min read
Waldemar Kindler
Read more
IoTSmart HomeEmbedded Systems

CRA Friday Facts: Cybersecurity Protects People, Not Just Data

Why connected toys, baby monitors, and health wearables count as important products class I, and what that means for manufacturers.

June 19, 2026
9 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsEmbedded Systems

CRA Friday Facts: Machinery Regulation and CRA, Two Duties, One Opportunity

Machinery Regulation certified ≠ CRA compliant. Why robot manufacturers must meet both frameworks and where the real synergies lie.

June 12, 2026
7 min read
Maximilian Heck
Read more
Smart HomeIoTIndustrial Components

CRA Friday Facts: Product End-of-Life Is Not the Finish Line

Discontinuing a product does not get you out of the CRA. Information duties, documentation retention, and secure data deletion guidance carry on.

June 5, 2026
10 min read
Maximilian Heck
Read more
Industrial MachineryIoTSmart Home

CRA Friday Facts: Collective Redress, Manufacturers in the Crosshairs

The CRA gives consumer protection organisations the right to sue manufacturers directly. Why regulators are not the only enforcement layer, and what that means in practice.

May 29, 2026
7 min read
Maximilian Heck
Read more
CRA ComplianceCyber Resilience ActIndustrial Machinery

Per-Unit Alarm: Why Inventory Manufactured in 2026 Becomes a CRA Compliance Risk in 2028

The EU CRA applies per individual unit at the moment of placing on the market. For Swiss manufacturers with 12 to 24 month inventory cycles, every serial number needs its own up-to-date patch status.

May 28, 2026
9 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsIoT

CRA Friday Facts: No Grandfathering, the Production Date Doesn't Count

There is no CRA grandfathering by production date. What counts is placing on the market, the day a unit actually reaches the EU market.

May 22, 2026
5 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsIoT

CRA Friday Facts: Why Your Supplier Can't Shield You From Liability

The CRA knows no liability delegation. Whoever places the product on the market is liable, even if suppliers develop and manufacture it.

May 15, 2026
5 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsIoT

CRA Friday Facts: Why SMEs Are Fully Affected Too

The CRA applies to every manufacturer with digital elements, 8 employees or 17,000. SME relief reduces bureaucracy, not the security standard.

May 8, 2026
4 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsIoT

CRA Friday Facts: CE Marking Done. Compliance Is an Ongoing Obligation

The CRA makes cybersecurity a continuous obligation. Without ongoing monitoring, documentation, and updates, conformity is lost, even after the EU declaration of conformity is signed.

May 1, 2026
5 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsIoT

CRA Friday Facts: Why Your Logo Makes You the Manufacturer

"We're just an importer." Wrong, the moment your logo is on the product. The CRA turns white-label vendors into manufacturers, with all the obligations.

April 24, 2026
4 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsIoT

CRA Friday Facts: When the CRA Hits Legacy Devices Too

Existing products aren't off the hook. From 11 Sept 2026, reporting obligations apply to all products on the market. And substantial modifications trigger the full CRA.

April 17, 2026
6 min read
Maximilian Heck
Read more
Industrial MachineryIndustrial ComponentsEmbedded Systems

CRA Friday Facts: Why a Single USB Port Hits the Offline Device

"Our machine runs offline." One USB port, an SD slot, or a service interface is enough to bring the product into CRA scope. Offline doesn't protect you.

April 10, 2026
4 min read
Maximilian Heck
Read more
CRASMESmall Enterprise

EU Cyber Resilience Act and SMEs: Every Relief Measure Available to Smaller Manufacturers

The CRA includes targeted SME relief measures — but they are unevenly distributed. Which measures apply, who benefits, and where medium-sized enterprises are left out.

March 23, 2026
10 min read
Maximilian Heck
Read more
SBOMSoftwareCRA Compliance

kunnus-scanner Is Now Open Source: Free SBOM Generation for CRA Compliance

We've open-sourced kunnus-scanner – a free CLI tool for generating SBOMs across 30+ ecosystems in SPDX and CycloneDX formats. Get started in minutes with Homebrew, Docker, or GitHub Actions.

March 10, 2026
4 min read
Waldemar Kindler
Read more
Industrial MachineryIndustrial ComponentsEmbedded Systems

Cyber Resilience Act and Switzerland: What Swiss Manufacturers Need to Know for EU Exports

The EU Cyber Resilience Act applies to Swiss manufacturers exporting to the EU — and Switzerland is preparing its own equivalent regulation via Motion 24.3810. Obligations, deadlines and concrete steps at a glance.

February 12, 2026
9 min read
Maximilian Heck
Read more
CRAComplianceSBOM

Why Manual EU CRA Compliance Fails (and Automation Is the Only Way)

EU Cyber Resilience Act manual compliance breaks at scale: SBOM upkeep, 24h ENISA reporting, vulnerability response — automation is the only path.

February 11, 2026
5 min read
Maximilian Heck
Read more
Vulnerability ManagementCRA ComplianceCyber Resilience Act

Vulnerability Management Under the CRA: Obligations, Processes, and Tools for Manufacturers

The Cyber Resilience Act makes vulnerability management mandatory. Learn what processes manufacturers must build – from detection through reporting to coordinated disclosure.

February 5, 2026
5 min read
Maximilian Heck
Read more
CRA ComplianceCyber Resilience ActCE Marking

20 Products You Didn't Expect – Why the Cyber Resilience Act Could Disrupt Your Business

RFID chips, plush toys, coffee machines – the CRA affects far more than the IT industry. 20 surprising product examples and what manufacturers need to know now.

February 1, 2026
10 min read
Maximilian Heck
Read more
Industrial AutomationCRA ComplianceCyber Resilience Act

CRA Requirements for Industrial Automation: What OEMs and Machine Builders Need to Know

The Cyber Resilience Act affects PLCs, HMIs, and industrial controllers. Learn which CRA requirements apply to industrial automation and how machine builders can implement compliance.

January 22, 2026
5 min read
Waldemar Kindler
Read more
SoftwareIoTEmbedded Systems

CRA Compliance Software Compared: Why Partial Solutions Fall Short

CRA compliance requires more than SBOM tools or vulnerability scanners alone. Learn why integrated platforms like Kunnus outperform fragmented approaches – and what to look for when choosing.

January 15, 2026
5 min read
Waldemar Kindler
Read more
CRA Conformity AssessmentCE MarkingCyber Resilience Act

CRA Conformity Assessment and CE Marking: A Step-by-Step Guide

How does the conformity assessment under the Cyber Resilience Act work? Learn which procedure applies to your product, what CE marking means, and how to create the EU declaration of conformity.

January 8, 2026
4 min read
Waldemar Kindler
Read more
CRASMECompliance

EU CRA Countdown: Your 2026–2027 Compliance Roadmap

EU CRA deadlines: Sept 2026 ENISA reporting, Dec 2027 full compliance. Step-by-step roadmap to hit each milestone — and avoid €15M in fines.

December 30, 2025
16 min read
Waldemar Kindler
Read more
Smart HomeConsumer ElectronicsCRA Compliance

Smart Home and CRA: What Consumer Electronics Manufacturers Need to Know

Smart home devices fall under the Cyber Resilience Act. Learn which CRA requirements apply to smart locks, thermostats, cameras, and other connected household products.

December 18, 2025
5 min read
Waldemar Kindler
Read more
IoTEmbedded SystemsSmart Home

Cyber Resilience Act Requirements: Complete Overview for Manufacturers

All CRA requirements at a glance – from security by design through SBOM obligations to reporting duties. The complete overview with links to detailed guidance for each requirement.

December 10, 2025
5 min read
Waldemar Kindler
Read more
CRA PenaltiesCRA FinesCyber Resilience Act

CRA Penalties for Non-Compliance: Fines, Product Recalls, and Consequences

What happens if you fail to comply with the Cyber Resilience Act? Learn about CRA fines up to 15 million euros, product recalls, and the consequences manufacturers face.

December 3, 2025
4 min read
Waldemar Kindler
Read more
CRA vs NIS2Cyber Resilience ActNIS2

CRA vs NIS2: Differences, Overlaps, and What Manufacturers Need to Know

The Cyber Resilience Act and NIS2 Directive are two EU cybersecurity regulations with different scopes. Learn how CRA and NIS2 differ and what obligations apply to manufacturers of digital products.

November 20, 2025
4 min read
Waldemar Kindler
Read more
SoftwareIoTCyber Resilience Act

EU Cyber Resilience Act & SaaS: When the CRA Applies (NIS2 Overlap)

Does SaaS fall under the EU Cyber Resilience Act? Where the boundary sits, how NIS2 overlaps, and when SaaS providers must comply with CRA obligations.

November 12, 2025
5 min read
Waldemar Kindler
Read more
Embedded SystemsCRA ComplianceCyber Resilience Act

CRA Compliance for Embedded Systems: Requirements, Deadlines, and Implementation

Embedded systems fall under the Cyber Resilience Act. Learn which CRA requirements apply to embedded devices, key deadlines, and how to implement compliance efficiently.

November 5, 2025
5 min read
Waldemar Kindler
Read more
CRAOEMManufacturing

Practical Steps to CRA Compliance

From CRA awareness to action: step-by-step guide for manufacturers based on BSI TR-03183-1. Achieve CRA compliance now.

October 29, 2025
13 min read
Waldemar Kindler
Read more
IoTEmbedded SystemsSmart Home

Cyber Resilience Act Scope: Which Products Are Affected?

Does your product fall under the Cyber Resilience Act? Learn exactly which products the CRA covers, which exemptions apply, and how product classification works.

October 28, 2025
5 min read
Waldemar Kindler
Read more
CRAOEMManufacturing

The CRA Is Coming: Why OEMs Must Act Now

The Cyber Resilience Act takes effect in 2027. OEMs and equipment manufacturers must act now to avoid penalties and market exclusion.

October 25, 2025
7 min read
Waldemar Kindler
Read more
SBOMIoTCRA Compliance

How to Create an SBOM for IoT Products: A Practical Guide to CRA Compliance

Learn how IoT manufacturers can create a Software Bill of Materials (SBOM), choose the right format, and meet the requirements of the EU Cyber Resilience Act.

October 15, 2025
5 min read
Waldemar Kindler
Read more
IoTEmbedded SystemsSmart Home

Cyber Resilience Act Summary: Key Facts at a Glance

A compact summary of the EU Cyber Resilience Act – objectives, scope, core obligations, deadlines, and penalties. With references to the original documents.

October 10, 2025
4 min read
Waldemar Kindler
Read more
AnnouncementCyber Resilience

Welcome to the Kunnus Blog

Insights on cyber resilience, risk management and robust security strategies. Our blog for modern organizations and manufacturers.

October 1, 2025
2 min read
Waldemar Kindler
Read more

CRA updates by email

Deadlines, official guidance, and myth-busting fact-checks on the Cyber Resilience Act — compact in our newsletter.

View newsletters