Methodology
How we write about the Cyber Resilience Act.
Regulatory content on this site is operational guidance for manufacturers, not legal advice. This page explains which sources we rely on, how we separate the regulation from our reading of it, how dates are kept, and what we refuse to publish.
Three kinds of statement, always labelled
Official requirement
A summary of what Regulation (EU) 2024/2847 says, kept close to the text, with the article or annex reference and a link to EUR-Lex. Where the text is ambiguous we say so instead of resolving it silently.
Interpretation
What we think an engineering, security or compliance team has to do to meet the requirement. It reflects practice and official guidance where it exists; it is not a legal opinion, and your advisers may reasonably differ.
Vellaci recommendation and workflow
How Vellaci supports the process, limited to features that exist in the product today. Product capabilities are never described as making a manufacturer compliant.
You will see these labels in the requirement tables on the CRA compliance software and product pages, and in the “direct answer” blocks, which state whether an answer is regulation, official guidance or operational interpretation.
Sources
Source hierarchy
| # | Source | Examples | How it is used |
|---|---|---|---|
| 1 | Regulation text | Regulation (EU) 2024/2847 as published in the Official Journal (EUR-Lex) | Governs. Every 'official requirement' on this site cites an article or annex of it. |
| 2 | Official guidance | European Commission, ENISA (including the Single Reporting Platform), national authorities such as the BSI | Used for how obligations are operated in practice, and dated, because guidance changes. |
| 3 | Technical standards and specifications | CycloneDX, SPDX, Package URL, ISO/IEC 29147 and 30111, RFC 9116, IEC 62443, CVSS | Used for formats and processes the regulation refers to without prescribing. |
| 4 | Security data sources | CISA KEV, FIRST EPSS, OSV, GitHub Advisory Database | Signals, never legal determinations. Shown with the time they were fetched. |
| 5 | Vellaci interpretation | Operational readings, recommendations and product workflows | Always labelled as interpretation or recommendation, never presented as the law. |
Dates
Publication, review and verification dates
Pages carry a 'last reviewed' or 'verified' date. It changes only when the content is re-checked against its sources — not when the layout changes. The sitemap's last-modified date follows the same rule.
Key regulatory facts used across the site and the product are kept in one registry with their source, section, verification date and rule version, so a correction reaches every page at once. Deadlines inside the product are computed from a versioned ruleset and stored with the rule version that produced them. The requirement map was last reviewed on 2026-10-05.
| Fact | Kind | Source | Verified |
|---|---|---|---|
| CRA Article 14 reporting obligations are in force as of 11 September 2026. The CRA’s general application date is 11 December 2027. | regulation | CRA Article 71 — Entry into force and application · Article 71(2) | 2026-09-28 |
| The CRA generally applies from 11 December 2027. Article 14 reporting applies earlier and has applied since 11 September 2026. | regulation | CRA Article 71 — Entry into force and application · Article 71(2) | 2026-09-28 |
| Manufacturers submit Article 14 notifications through ENISA’s Single Reporting Platform (SRP). Vellaci can prepare and track a case but does not submit on the manufacturer’s behalf. | official guidance | ENISA — Single Reporting Platform (SRP) | 2026-09-28 |
| Article 14 deadlines are calculated from when the manufacturer becomes aware. Preserve the human-confirmed time, timezone, confirming person, supporting evidence, and any later correction; ticket creation time is not silently treated as awareness. | operational interpretation | CRA Article 14 — Reporting obligations of manufacturers · Article 14(2) and 14(4) | 2026-09-28 |
What we do not publish
Claims we refuse to make
No compliance guarantees
No software makes a product CRA compliant. Conformity is demonstrated through the assessment route for the product's category; Vellaci records the process and the evidence.
No invented customers or results
No logos, quotes, case studies or metrics are shown until a customer has approved them in writing with a measured outcome. Until then the section is simply absent.
No certifications we do not hold
Security certifications appear on the Trust Center only once obtained. Today none is claimed.
No automated legal determinations
Scope, classification and reportability are decided by the manufacturer. The product surfaces signals and records who decided, when and why.
Corrections
Found an error?
Write to hello@vellaci.ch with the page and the source you are relying on. We correct factual errors, update the review date and, where a correction changes an obligation or a deadline, say so on the page.