Cybellum
Cyber Resilience Act Compliance and Support Guide
Pages
8
Time to read
9 mins
Publication
Language
English
Pages
8
Time to read
9 mins
Publication
Language
English
This guide details the Cyber Resilience Act (CRA), a proposed EU regulation aimed at enhancing cybersecurity and resilience for products with digital elements. The CRA, set to be implemented in 2024, outlines essential security requirements that manufacturers must adhere to, including the necessity for products to be delivered without known exploitable vulnerabilities and to maintain secure default configurations. The document also discusses the scope of the CRA, which applies to various products, including medical devices and motor vehicles, while noting exceptions for national security-related items. Additionally, it reviews how the Cybellum Product Security Platform aligns with CRA requirements, providing capabilities for vulnerability management, incident response, and compliance tracking. The guide emphasizes the importance of maintaining a secure software supply chain and outlines specific processes manufacturers must implement, such as creating Software Bill of Materials (SBOM) and addressing vulnerabilities promptly.