Boxfish Labs home
Boxfish Labs
  • Solutions
  • Resources
  • About
  • Labs
Book a Call
Boxfish Labs home
Boxfish Labs

Menu

    • By service
      • Information Security Advisory
      • Virtual CISO (vCISO)
      • External DPO
      • Data Residency & Sovereignty
      • Human-centred cybersecurity awareness
      • Security Check for Vibe-Coded Apps
    • By Framework
      • GDPR
      • ISO 27001
      • DORA
      • TISAX
      • EU AI Act
      • Cyber Resilience Act
    • Audience
      • Startups and Scaleups
      • Fintech
      • Technology suppliers
      • Educators
    • View all solutions
    • Articles
    • Courses and Webinars
    • Downloads
    • Compliance Glossary
    • CRA applicability quiz
    • Privacy toolboxNEW
    • View all resources
    • About us
    • News
    • Social impact
    • Pilot partner program
    • Referral program
    • Contact
    • About Labs
    • Games
    • Privacy toolbox

Featured

Dot-matrix letters CRA on a black grid background

Does your software or hardware product need to comply with the EU Cyber Resilience Act?

Take the test
Book a Call
Resources

Learn, practise, and look things up

Articles, courses, downloads, and a free security, privacy and compliance glossary - practical guidance you can use across your team.

Articles

News, insights, and practical guidance on security, privacy, and cyber resilience.

View all articles

Human Factors

10 Essential Cybersecurity Training Topics every EU organisation should include in its cybersecurity awareness programme

From phishing and AI deepfakes to GDPR, ransomware, secure AI use, and incident reporting - the practical topics EU organisations need in cybersecurity awareness training.

Read

Impact of AI

Same Cloud, Different Risk: What CTOs Need to Acknowledge About Enterprise AI

Enterprise AI from Azure, AWS or Google Cloud can sit under familiar contracts and controls - but the use-case risk is not the same as SharePoint or Drive. A practical middle ground for CTOs between a blanket ban and uncontrolled adoption.

Read

Privacy

Can You Delete Yourself From the Internet? A Guide to Digital Erasure

You can shrink your digital footprint, but you usually cannot erase yourself completely. A practical guide to account deletion, GDPR and UK erasure rights, data brokers, and the limits of the right to be forgotten.

Read

Courses

Structured learning for people and teams who need security, privacy, and compliance habits they can keep.

View all courses

CRA reporting starts on 11 September. Is your product team ready?

A practical live webinar for software and connected-product teams selling in the EU. Translate the 11 September Article 14 reporting milestone into product ownership, triage, and a 30-day readiness plan.

View course

Cyber Hygiene Essentials

A free, beginner-friendly introduction to safer everyday internet habits.

View course

Shadow AI at Work

AI tools can make work faster, but they can also expose sensitive business information. A live, practical course for safer AI use at work.

View course

Downloads

Guides, checklists, and tools you can use today.

View all downloads

CRA Executive Summary

In this document, we explain the main purpose of the Cyber Resilience Act, which products and businesses may be affected, and the key responsibilities for manufacturers and other organisations placing digital products on the EU market.

Does the EU Cyber Resilience Act apply to your product?

Take a short applicability assessment and get a preliminary result with next steps.

14

months

5

days

until wider CRA requirements apply

Start applicability assessment

Security, privacy and compliance glossary

Plain-language definitions for GDPR, ISO 27001, DORA, the EU AI Act, the Cyber Resilience Act, and related terms. This is a short preview - open the full glossary to browse by letter.

Open full glossary

GDPR

General Data Protection Regulation. The EU law that sets rules for processing personal data, including lawful bases, individual rights, security, and accountability for controllers and processors.

View term

DORA

Digital Operational Resilience Act. EU rules for financial entities covering ICT risk, incident reporting, testing, and oversight of critical ICT third-party providers.

View term

Cyber Resilience Act

EU product-security law for products with digital elements. It expects manufacturers to design, maintain, and document security throughout the product lifecycle, including vulnerability handling.

View term

EU AI Act

The European Union’s risk-based law for AI systems. Obligations scale with risk, from transparency for some uses to strict requirements for high-risk systems affecting safety or fundamental rights.

View term

ISO 27001

An international standard for establishing, running, and improving an ISMS. Certification is optional; the value is a repeatable way to manage risk, controls, and evidence.

View term

Access control

The rules and technical measures that decide who can view, change, or use information, systems, and services. Proportionate access control limits privileges to what people need for their role.

View term

Privacy by design

Building data-protection into products and processes from the start, rather than adding a notice at the end. It covers minimisation, purpose limits, security, and user rights in everyday workflows.

View term

Shadow AI

The unsanctioned use of AI tools with work data. It can leak information, create unapproved processing, and bypass security or privacy rules unless teams have clear, usable alternatives.

View term

Want to go deeper?

Browse insights from Boxfish Labs, or get in touch to talk through what your team needs next.

Book a Call
Boxfish Labs

Human-centred security for teams that need to move fast.

LinkedInInstagramYouTube

Explore

  • Solutions
  • Resources
  • About
  • Labs

Legal

  • Privacy Policy
  • Impressum

© 2026 Boxfish Labs

Facebook