Form Submission

The CRA Playbook for Manufacturers of Products with Digital Elements

A practical, chapter-by-chapter guide to EU Cyber Resilience Act compliance from the IoT M2M Council.

The EU Cyber Resilience Act (CRA) fundamentally changes how manufacturers of connected products must approach cybersecurity. Full enforcement begins December 11, 2027, with phased obligations starting as early as June 2026. The CRA Playbook is a practical guide that helps engineering, product security, and compliance teams prepare.

Download the first six chapters:

  • Chapter 1: Secure-by-Design for Products with Digital Elements
  • Chapter 2: Vulnerability Management and the September 2026 Reporting Obligation
  • Chapter 3: Software Bill of Materials: Generation, Format, and Maintenance
  • Chapter 4:Conformity Assessment Routes and Notified Bodies
  • Chapter 5: Technical Documentation
  • Chapter 6: Secure Updates and OTA Infrastructure

Additional chapters will be published over the coming months. Subscribe to the IoT Security & Public Policy Newsletter to receive them as they are released.

.

Click here to view our Privacy Policy / Terms & Conditions