CRANIS2
The CRA works on the product, NIS2 on the company. Many device manufacturers fall under both without knowing it: manufacturing is among the Annex II NIS2 sectors. What changes, how much of the work done for the CRA also counts for NIS2, and where two distinct obligations remain. With references to the articles.
19 August 2026·6 min read
CRA
The 24 hours for the early warning run on a Saturday too, and a specific person makes them run. Who the Assigned Representative on the ENISA platform is, why it is not the CRA authorised representative, and how to choose it from the micro-firm to the multinational.
12 August 2026·7 min read
CRA
Not every report from outside triggers the CRA obligation. The trigger is narrow and defined. How a company decides, often in 24 hours and maybe over a closure, whether to open a notification on the ENISA platform. With a concrete case: the compromised WiFi sensor.
12 August 2026·9 min read
CRA
"ISO 9001 compliant" doesn't mean "almost CRA compliant". It's the costliest illusion: the quality system is an advantage, but reusing it badly — assuming that form equals substance — is the mistake that recurs most often. Where reuse becomes dangerous.
29 July 2026·2 min read
ISO 42001IEC 62443AI
Put an AI model in an OT product and you get two risks in different languages. 62443 secures the box, 42001 the brain: how to integrate them, in six points.
22 July 2026·6 min read
AIAI ACTISO 42001
Many rank their AI use cases by expected return. It's the wrong criterion: what decides which one ships first is the AI Act risk classification and the maturity of the data. How a regulation becomes a product decision.
29 June 2026·8 min read
ISO 42001AI ACTAI
ISO 42001 grants no presumption of conformity with the AI Act — but for product builders its value is operational and available now. Why starting pays off.
16 June 2026·6 min read
No articles with this tag yet.