Shop
Books and guides to help your team navigate EU compliance — written by practitioners, for practitioners.
Products by type

Risk, Evidence and Conformity
The missing guide for default products with digital elements; exploring risk assessment, evidence management, and compliance documentation under the EU Cyber Resilience Act.
Written for teams owning risk assessment, evidence and conformity documentation for products with digital elements.
Learn moreAvailable only with a workshop or a consulting engagement, not sold on its own.

Modular Compliance
A practical guide to navigating the EU Cyber Resilience Act — classifying products, choosing conformity assessment modules, and building sustainable compliance processes.
Written for software manufacturers preparing for CRA self-assessment or third-party evaluation.
Learn more
Manufacturing European Software
This book has a name for compliance that satisfies a regulator without making software any safer: cybersecurity theatre. Under the Cyber Resilience Act, following the rules could fall short of actually achieving them.
Written for product leaders, engineering leaders, and non-technical stakeholders shipping software into the EU.
Learn more
Free this weekDownstream Post-Market Modifications and Break-Glass Agreements
An emergency fix to a product you do not manufacture can assign "manufacturer" obligations and reporting duties under the Cyber Resilience Act. This dossier maps which post-market modifications and break-glass actions cross that line, and how to agree who carries the obligation before an incident forces the answer.
Written for product security, compliance and engineering teams handling post-market fixes on someone else's product.
Learn moreFree until 1 October
Get it free
20% offArticle 14 Reporting beyond the Support Period
Ending a product's support period does not end your Cyber Resilience Act's Article 14 reporting duty. This dossier argues that duty only ends when your company does, tracing that position through the Regulation's text, the adopted European Commission guidance, and the wider EU product-safety framework.
Written for general counsel and compliance leads deciding whether a discontinued product's Cyber Resilience Act reporting duty has actually ended.
Learn moreFree until 24 September
Get it free
Vulnerability Handling under CRA: the 11 September 2026 Reporting Obligations
From 11 September 2026, the Cyber Resilience Act's vulnerability and incident reporting obligations apply to manufacturers, and they cover products already on the market, not just new ones. This dossier sets out the 24-hour and 72-hour reporting deadlines, and the 14-day final-report deadline for actively exploited vulnerabilities: what actually triggers them and how to be ready before the clock starts.
Written for product security and compliance leads, and whoever owns incident response, at any manufacturer with a product with digital elements already on the EU market.
Learn moreFree until 17 September
Get it free
Cyber Vulnerability Reporting: Fundamentals
A practical, self-paced foundation course on vulnerability and incident reporting under the EU Cyber Resilience Act. In partnership with ECI Ireland.
Learn moreMore compliance resources, templates, and toolkits coming soon. Subscribe to our newsletter to be the first to know.