Stefan Coetzeecreated 2026-05-12updated 2026-05-121 min readanchors
Vault note, not reviewed against the source. Written in the knowledge vault on 2026-05-12 by models working with Stefan Coetzee and published as it stands, with private addresses, e-mail addresses and an employer name redacted. Check claims against the primary source before relying on them.
CRA Anchors
Primary text
Regulation (EU) 2024/2847 — Cyber Resilience Act. Published OJEU 20 November 2024.
Adjacent regulation
NIS2 (Dir 2022/2555) — operator cybersecurity.
EU AI Act (Reg 2024/1689) — high-risk AI products.
MDR (Reg 2017/745) — medical devices (CRA excludes).
UN R155 / R156 — vehicles (CRA excludes).
Product Liability Directive (Dir 2024/2853) — product liability including AI.
Reference standards
EN 18031 — cybersecurity for radio equipment (RED Delegated Act).
ETSI EN 303 645 — consumer IoT cybersecurity baseline.
ISO/IEC 27034 — application security.
ISO/IEC 15408 (Common Criteria) — IT product security evaluation.
Operating bodies
European Commission — DG CNECT.
ENISA — implementation guidance.
Member State market surveillance authorities — enforcement.
Notified Bodies for third-party conformity assessment of important / critical products.