Cyber Resilience Act · Software

CE-Marked Code by Kai London

Software placed on the EU market is moving into the world of product regulation: essential requirements, conformity assessment, technical documentation and a mark on the box. For most software organisations this is unfamiliar territory. CE-Marked Code translates it into engineering and release practice.

Coming soonAll books

What the book covers

Scope and classification

Which software counts as a product with digital elements, and how product classes change the obligations.

Essential requirements

Secure-by-default configuration, hardening, update capability and data minimisation expressed as engineering requirements.

Conformity assessment

Self-assessment versus third-party routes, harmonised standards, and what a declaration of conformity commits you to.

Technical documentation

Assembling and maintaining the file, including SBOM, risk assessment and test evidence.

Support periods and updates

Committing to a support window and being able to deliver security updates across it.

Open source and reuse

Handling third-party and open-source components, and the responsibilities that travel with them.

General guidance, not legal advice; take qualified advice on how the CRA applies to your products. Independent, with no endorsement by or affiliation with any regulator, notified body or standards organisation.

CRAIEC 62443-4-1ISO 27034SBOM

Who it is for

Software vendors and device manufacturers, product and engineering leadership, product security and PSIRT teams, regulatory affairs, and legal and commercial functions.

About the author

Professor Kai London — CISSP, CISM.

An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.