Cyber Resilience Act Compliance Handbook 2027 by Kai London
The CRA makes security a condition of market access: no conformity, no CE mark, no sale. This handbook takes a manufacturer from product classification to technical documentation, and builds the vulnerability-handling machine the regulation assumes you already run.
Available on Amazon. An independent practitioner guide — not legal advice, and not affiliated with or endorsed by any regulator or notified body.
What is inside
Scope and classification
What counts as a product with digital elements, which class it lands in, and who carries the obligation in a supply chain.
Essential cybersecurity requirements
Secure-by-default configuration, attack-surface reduction and update mechanisms translated into engineering backlog items.
SBOM and vulnerability handling
Component inventory, coordinated disclosure, remediation timelines and security update delivery across the support period.
Reporting obligations
Actively exploited vulnerabilities and severe incidents — who must be told, how fast, and how the internal trigger works.
Conformity assessment
Routes to conformity, technical documentation, the EU declaration and where a notified body enters the process.
Open source and suppliers
Upstream components, steward obligations and contractual flow-down that keeps third-party code from becoming your defect.
Who it is for: product security leaders and engineering managers at device and software manufacturers, regulatory affairs and compliance teams, importers and distributors, and CISOs whose company now ships regulated products.
Under the CRA, an unpatched product is not a support problem. It is a market access problem.
About the author
Professor Kai London — CISSP, CISM.
An internationally recognised cybersecurity executive, board advisor and Founder & CEO of Quantum AI Systems Security LLC, writing at the convergence of AI, governance and operational resilience. Honorary Professor and Researcher at UCL.