Sembra che tu preferisca leggere in italiano.

Passa all'italiano

GUIDES · CYBERSECURITY

Guides on the CRA, NIS2 and IEC 62443

What the CRA, NIS2 and IEC 62443 require from makers of machinery and connected products — reference explanations, kept up to date.

← All guides

NIS2, DORA and the CRA compared: object, legal nature and scope

Three European cybersecurity acts, three different levels: the CRA regulates products, NIS2 organisations, DORA the financial sector. What each text says about object, legal form, dates of application and addressees, and how they fit together. A guide from the official sources, with references to the articles.

NIS2: what it is, who it applies to, deadlines and requirements

The NIS2 directive and its Italian transposition (Legislative Decree 138/2024) in a reference guide: what changes compared with NIS1, who the essential and important entities are, the compliance calendar set by ACN, and the requirements on governance, risk management and incident notification. From the official sources, with references to the articles.

The CRA deadlines, and what you must have done for each

The Cyber Resilience Act doesn't start all at once. There are three dates that matter, 11 September 2026, 11 December 2027, and the end of the RED's cyber requirements, and for each a minimum state you must be able to demonstrate. The operational timeline, with references to the articles.

The CRA in one hour: what changes for anyone who builds connected products

The Cyber Resilience Act is not a box to tick before CE marking: it's an obligation that follows the product for its whole life. What a product with digital elements is, the three obligations that didn't exist before, and how to turn their requirements into development decisions. With precise article references.

CRA and ISO 9001: what to hook onto the quality system and what to build

The CRA↔ISO 9001 map: which quality-system mechanisms you extend to the Cyber Resilience Act almost frictionlessly, which three processes you have to build from scratch, and where the 9001 helps more than it seems. With references to the CRA articles and the ISO 9001 clauses.

The CRA Single Reporting Platform: a complete guide to reporting

From 11 September 2026, actively exploited vulnerabilities and severe incidents are reported on a single ENISA platform. What the SRP is, who registers, what goes into each notification, who receives it and within how many hours. A guide from the official sources, with references to the CRA articles and to ENISA guidance.

Not sure where to start?

45 free minutes to map your regulatory exposure and see what it means for your product.

Book the Regulatory Spark