Methodology

How we write about the Cyber Resilience Act.

Regulatory content on this site is operational guidance for manufacturers, not legal advice. This page explains which sources we rely on, how we separate the regulation from our reading of it, how dates are kept, and what we refuse to publish.

Three kinds of statement, always labelled

Official requirement

A summary of what Regulation (EU) 2024/2847 says, kept close to the text, with the article or annex reference and a link to EUR-Lex. Where the text is ambiguous we say so instead of resolving it silently.

Interpretation

What we think an engineering, security or compliance team has to do to meet the requirement. It reflects practice and official guidance where it exists; it is not a legal opinion, and your advisers may reasonably differ.

Vellaci recommendation and workflow

How Vellaci supports the process, limited to features that exist in the product today. Product capabilities are never described as making a manufacturer compliant.

You will see these labels in the requirement tables on the CRA compliance software and product pages, and in the “direct answer” blocks, which state whether an answer is regulation, official guidance or operational interpretation.

Sources

Source hierarchy

#SourceExamplesHow it is used
1Regulation textRegulation (EU) 2024/2847 as published in the Official Journal (EUR-Lex)Governs. Every 'official requirement' on this site cites an article or annex of it.
2Official guidanceEuropean Commission, ENISA (including the Single Reporting Platform), national authorities such as the BSIUsed for how obligations are operated in practice, and dated, because guidance changes.
3Technical standards and specificationsCycloneDX, SPDX, Package URL, ISO/IEC 29147 and 30111, RFC 9116, IEC 62443, CVSSUsed for formats and processes the regulation refers to without prescribing.
4Security data sourcesCISA KEV, FIRST EPSS, OSV, GitHub Advisory DatabaseSignals, never legal determinations. Shown with the time they were fetched.
5Vellaci interpretationOperational readings, recommendations and product workflowsAlways labelled as interpretation or recommendation, never presented as the law.

Dates

Publication, review and verification dates

Pages carry a 'last reviewed' or 'verified' date. It changes only when the content is re-checked against its sources — not when the layout changes. The sitemap's last-modified date follows the same rule.

Key regulatory facts used across the site and the product are kept in one registry with their source, section, verification date and rule version, so a correction reaches every page at once. Deadlines inside the product are computed from a versioned ruleset and stored with the rule version that produced them. The requirement map was last reviewed on 2026-10-05.

FactKindSourceVerified
CRA Article 14 reporting obligations are in force as of 11 September 2026. The CRA’s general application date is 11 December 2027.regulationCRA Article 71 — Entry into force and application · Article 71(2)2026-09-28
The CRA generally applies from 11 December 2027. Article 14 reporting applies earlier and has applied since 11 September 2026.regulationCRA Article 71 — Entry into force and application · Article 71(2)2026-09-28
Manufacturers submit Article 14 notifications through ENISA’s Single Reporting Platform (SRP). Vellaci can prepare and track a case but does not submit on the manufacturer’s behalf.official guidanceENISA — Single Reporting Platform (SRP)2026-09-28
Article 14 deadlines are calculated from when the manufacturer becomes aware. Preserve the human-confirmed time, timezone, confirming person, supporting evidence, and any later correction; ticket creation time is not silently treated as awareness.operational interpretationCRA Article 14 — Reporting obligations of manufacturers · Article 14(2) and 14(4)2026-09-28

What we do not publish

Claims we refuse to make

No compliance guarantees

No software makes a product CRA compliant. Conformity is demonstrated through the assessment route for the product's category; Vellaci records the process and the evidence.

No invented customers or results

No logos, quotes, case studies or metrics are shown until a customer has approved them in writing with a measured outcome. Until then the section is simply absent.

No certifications we do not hold

Security certifications appear on the Trust Center only once obtained. Today none is claimed.

No automated legal determinations

Scope, classification and reportability are decided by the manufacturer. The product surfaces signals and records who decided, when and why.

Corrections

Found an error?

Write to hello@vellaci.ch with the page and the source you are relying on. We correct factual errors, update the review date and, where a correction changes an obligation or a deadline, say so on the page.