21 days to go until the first phase of the EU Cyber Resilience Act comes into force. Are you ready?
Platanor Technologies
Insights

Insights & Resources

Practical guidance on embedded security, IoT best practices, and CRA regulations

Open source

We open-sourced our CRA, RED, NIS2 and CSA knowledge base

One repo covering every EU rule that touches hardware and IoT security - fact-checked, structured, and free under CC BY 4.0. Install it as a Claude Skill and ask it directly which rules apply to your product.

View the repo on GitHub
Platanor's open source Hardware Compliance Knowledge Base on GitHub - CRA, RED, NIS2 and CSA in one place, answering questions like which rules apply, notified body or self-assess, and CRA or RED or both
CE Marking for Connected Devices: A Practical Step-by-Step Guide to CRA and RED Compliance
CRA ComplianceFull article

CE Marking for Connected Devices: A Practical Step-by-Step Guide to CRA and RED Compliance

CE marking isn't one stamp - it's the visible outcome of separate CRA and RED assessments running in parallel. A step-by-step walkthrough of self-assessment: product classification, technical documentation, Module A, the EU Declaration of Conformity, and the post-market duties that start once the mark goes on.

Aug 12, 20269 min read
CE Marking and the CRA: What the Mark Certifies - and What It Does Not
CRA ComplianceFull article

CE Marking and the CRA: What the Mark Certifies - and What It Does Not

Most manufacturers assume a CE mark means someone tested their product and approved it. It does not. Under the CRA the mark is a declaration you sign yourself, and it is not a second mark on top of the one your device may already carry under RED. Here is what it means, and when it starts to matter.

Jul 31, 20268 min read
What Is Device Identity in IoT - and What CRA Actually Requires
IoT SecurityFull article

What Is Device Identity in IoT - and What CRA Actually Requires

CRA does not mandate device identity by name. But on a fleet of identical devices it is the most defensible answer to the access control requirement in Annex I. Here is what it actually means for IoT manufacturers, what the regulation does and does not say, and how to add it without a redesign.

Jul 23, 20268 min read
IoT Threat Modeling: A Step-by-Step Guide for Hardware Manufacturers
IoT SecurityFull article

IoT Threat Modeling: A Step-by-Step Guide for Hardware Manufacturers

Learn how to build a threat model for your IoT device using STRIDE. A practical step-by-step guide for hardware manufacturers preparing for EU CRA compliance.

Jul 14, 202614 min read
CRA Article 14: Vulnerability Reporting Obligations Starting September 2026 — What Manufacturers Must Prepare Now
CRA ComplianceFull article

CRA Article 14: Vulnerability Reporting Obligations Starting September 2026 — What Manufacturers Must Prepare Now

CRA Article 14 mandatory vulnerability reporting starts September 11, 2026. What IoT and hardware manufacturers must have in place technically and operationally before the deadline.

Jul 6, 202612 min read
Secure OTA Updates for IoT Devices: What Can Go Wrong and How to Build It Right
IoT SecurityFull article

Secure OTA Updates for IoT Devices: What Can Go Wrong and How to Build It Right

Unsigned OTA updates are one of the most common IoT security failures. Here is what a correct secure firmware update architecture looks like - and what CRA requires from it.

Jun 20, 20267 min read
SBOM for IoT Manufacturers: What CRA Requires and How to Create One
IoT SecurityFull article

SBOM for IoT Manufacturers: What CRA Requires and How to Create One

CRA requires an SBOM for every connected product. Here is what it must contain, which format to use, how to generate it for embedded firmware, and how to keep it current post-release.

Jun 16, 20267 min read
June 11, 2026: What This CRA Milestone Actually Starts for Manufacturers
CRA ComplianceFull article

June 11, 2026: What This CRA Milestone Actually Starts for Manufacturers

On June 11, 2026, the EU activated the legal rules for building its CRA conformity assessment infrastructure. What this milestone means for IoT and hardware manufacturers - and why the window to prepare is closing.

Jun 11, 20267 min read
What is Secure Boot - and Why Every IoT Device Needs It
IoT SecurityFull article

What is Secure Boot - and Why Every IoT Device Needs It

Secure boot verifies that your device runs only firmware you signed. Here is how it works, why CRA treats it as a baseline requirement, and what a correct implementation looks like on Nordic nRF and STM32.

Jun 10, 20269 min read
How to Classify Your Product Under CRA: Default, Important Class I, or Class II
CRA ComplianceFull article

How to Classify Your Product Under CRA: Default, Important Class I, or Class II

Your CRA product category determines your entire compliance path. Here is how to correctly classify your IoT or hardware device under the Cyber Resilience Act - and why getting it wrong costs time and money.

Jun 3, 20267 min read
September 11, 2026: The First CRA Deadline Most Manufacturers Are Not Ready For
CRA ComplianceFull article

September 11, 2026: The First CRA Deadline Most Manufacturers Are Not Ready For

September 11, 2026 is the first binding CRA deadline - and it applies to products already on the EU market. Here is what the 24-hour reporting obligation requires and how to prepare.

Jun 3, 20268 min read
EU Cyber Resilience Act: A Complete Guide for IoT and Hardware Manufacturers (2026)
CRA ComplianceFull article

EU Cyber Resilience Act: A Complete Guide for IoT and Hardware Manufacturers (2026)

The EU Cyber Resilience Act requires IoT and hardware manufacturers to comply by December 2027. Deadlines, requirements, SBOM, penalties up to €15M - complete guide by Platanor.

May 30, 202610 min read