CRA and EN 18031 compliance notes for embedded and IoT teams.
The CRA's 24h/72h/14-day vulnerability reporting clocks start on 11 September 2026 — the same day the Single Reporting Platform itself is scheduled to go live, not before. Here's what's confirmed, what isn't, and what you can prepare regardless.
2 September 2026 · 6 min read
The Cyber Resilience Act ties your support-period obligation to whatever ships in the image. The fewer things you can't easily update, the cheaper that obligation gets. A practical case for separating bootchain/kernel/HAL from libs/apps/comms stacks.
17 August 2026 · 5 min read
One command gets you a spec-compliant SBOM for your ESP32 firmware. The CRA's technical file wants a lot more than that. Here is exactly where esp-idf-sbom's output lands in Annex VII, and what you still have to write yourself.
23 July 2026 · 6 min read
The CRA deadlines get the headlines, but if your product has radio and touches the internet, EN 18031 has applied since August 2025. Here is what applies today, what carries over to 2027, and the harmonisation fine print that can force a Notified Body into your project.
16 July 2026 · 7 min read