Boxfish Labs home
Boxfish Labs
  • Solutions
  • Resources
  • About
  • EN
  • DE
  • HU
Book a Call
Boxfish Labs home
Boxfish Labs

Menu

    • By service
      • Information Security Advisory
      • External CISO
      • External DPO
      • Data Residency & Sovereignty
      • Human-Centric Cybersecurity Awareness
    • By Framework
      • GDPR
      • ISO 27001
      • DORA
      • TISAX
      • EU AI Act
      • Cyber Resilience Act
    • Audience
      • Startups and Scaleups
      • Fintech
      • Technology suppliers
      • Educators
      • Individuals
    • View all solutions
    • Articles
    • Courses and Webinars
    • Downloads
    • Compliance Glossary
    • CRA applicability quiz
    • View all resources
    • About us
    • Pledge
    • Social impact
    • Partnerships
    • Contact
    • View about Boxfish Labs

Featured

Dot-matrix letters CRA on a black grid background

Pass EU Cyber Resilience Act (CRA) applicability assessment test

  • EN
  • DE
  • HU
Book a Call
Resources

Learn, practise, and look things up

Articles, courses, downloads, and a free security, privacy and compliance glossary - practical guidance you can use across your team.

Articles

News, insights, and practical guidance on security, privacy, and cyber resilience.

View all articles

Cyber Resilience Act

What Is the EU Cyber Resilience Act?

A guide to the EU Cyber Resilience Act (CRA) that provides the overview of the most important aspects, such as, who it applies to, key compliance dates, product risk categories, SBOM and vulnerability-reporting requirements, potential penalties, and the difference between the CRA and NIS2.

Read

Cyber Resilience Act

CRA Readiness in Germany, Europe and Global Markets

Awareness of the Cyber Resilience Act is rising faster than operational readiness. Survey evidence from German industry, European SMEs, and the global open-source ecosystem shows where product teams still need ownership, evidence, and supplier information.

Read

Cyber Resilience Act

Cyber Resilience Act Reporting Obligations: Who Must Report, When, and How

Learn who must report under the EU Cyber Resilience Act, which cybersecurity events trigger reporting, the 24-hour and 72-hour deadlines, and how to prepare your team.

Read

Courses

Structured learning for people and teams who need security, privacy, and compliance habits they can keep.

View all courses

CRA reporting starts on 11 September. Is your product team ready?

A practical live webinar for software and connected-product teams selling in the EU. Translate the 11 September Article 14 reporting milestone into product ownership, triage, and a 30-day readiness plan.

Learn more

Cyber Hygiene Essentials

A free, beginner-friendly introduction to safer everyday internet habits.

Learn more

Shadow AI at Work

AI tools can make work faster, but they can also expose sensitive business information. A live, practical course for safer AI use at work.

Learn more

Downloads

Guides, checklists, and tools you can use today.

View all downloads

CRA Executive Summary

In this document, we explain the main purpose of the Cyber Resilience Act, which products and businesses may be affected, and the key responsibilities for manufacturers and other organisations placing digital products on the EU market.

1

day until CRA reporting starts

Does the EU Cyber Resilience Act (CRA) apply to your product?

Take a short applicability assessment and get a preliminary result with next steps.

Start applicability assessment
Start applicability assessment

Security, privacy and compliance glossary

Plain-language definitions for GDPR, ISO 27001, DORA, the EU AI Act, the Cyber Resilience Act, and related terms. This is a short preview - open the full glossary to browse by letter.

Open full glossary

GDPR

General Data Protection Regulation. The EU law that sets rules for processing personal data, including lawful bases, individual rights, security, and accountability for controllers and processors.

Learn more

DORA

Digital Operational Resilience Act. EU rules for financial entities covering ICT risk, incident reporting, testing, and oversight of critical ICT third-party providers.

Learn more

Cyber Resilience Act

EU product-security law for products with digital elements. It expects manufacturers to design, maintain, and document security throughout the product lifecycle, including vulnerability handling.

Learn more

EU AI Act

The European Union’s risk-based law for AI systems. Obligations scale with risk, from transparency for some uses to strict requirements for high-risk systems affecting safety or fundamental rights.

Learn more

ISO 27001

An international standard for establishing, running, and improving an ISMS. Certification is optional; the value is a repeatable way to manage risk, controls, and evidence.

Learn more

Access control

The rules and technical measures that decide who can view, change, or use information, systems, and services. Proportionate access control limits privileges to what people need for their role.

Learn more

Privacy by design

Building data-protection into products and processes from the start, rather than adding a notice at the end. It covers minimisation, purpose limits, security, and user rights in everyday workflows.

Learn more

Shadow AI

The unsanctioned use of AI tools with work data. It can leak information, create unapproved processing, and bypass security or privacy rules unless teams have clear, usable alternatives.

Learn more
Get started

Want to go deeper?

Browse insights from Boxfish Labs, or get in touch to talk through what your team needs next.

Book a Call
Boxfish Labs

Human-centred security for teams that need to move fast.

LinkedInInstagramYouTubeFacebook

Explore

  • Solutions
  • Resources
  • About

Legal

  • Privacy Policy
  • Impressum

© 2026 Boxfish Labs