Coverage
Regulations and standards explained
Each framework has an explanation of its scope and requirements, with links to relevant assessments where available. The Machinery Regulation page is a focused explainer without a questionnaire.
Grouped by the work they concern. Some frameworks appear in more than one group. Each overview explains its scope and who it applies to.
Product requirements
Regulation (EU) 2024/2847
Cyber Resilience Act
Regulation (EU) 2024/2847 — cybersecurity as a condition of market access for products with digital elements.
Open frameworkIEC 62443-4-2
IEC 62443-4-2
The technical counterpart to 4-1: the security capabilities a component must provide, rated on the capability security levels an evaluator works to.
Open frameworkRED · Delegated Regulation (EU) 2022/30 · EN 18031
RED (EN 18031)
The Radio Equipment Directive cybersecurity requirements, harmonised by EN 18031 — network protection, personal data, and anti-fraud for internet-connected radio equipment.
Open frameworkRegulation (EU) 2023/1230
Machinery Regulation
Cybersecurity requirements affecting machinery safety, the 2027 transition and the interaction with the CRA. Explainer only; no Machinery Regulation assessment.
Open framework
Development process
Regulation (EU) 2024/2847
Cyber Resilience Act
Regulation (EU) 2024/2847 — cybersecurity as a condition of market access for products with digital elements.
Open frameworkIEC 62443-4-1
IEC 62443-4-1
The secure product development lifecycle standard certification bodies audit against, and the practical way to evidence CRA process obligations.
Open framework
Organisation
Directive (EU) 2022/2555
NIS2
Directive (EU) 2022/2555 — the security and reporting duties on operators of essential and important services, and the customers who demand product-side evidence from manufacturers.
Open frameworkISO/IEC 27001:2022 · Annex A · ISMS
ISO/IEC 27001
ISO/IEC 27001:2022 — a standard for information security management systems. Its Annex A controls can point to evidence relevant to NIS2, IEC 62443 and CRA work, but each applicable requirement must be checked separately.
Open framework
Get in touch
Not sure which of these apply to you?
Several of these frameworks can reach the same product at once, and the overlap is where most of the wasted effort hides. Tell us what you build and where you sell it, and we will map which regimes apply and how they fit together.
We reply within two working days.
Full contact detailsOpens our scheduling page in a new tab — pick a slot that suits you.
Worth including in a first message
- What the product is, and whether it contains software or connects to a network.
- Which markets you sell into, and your role — manufacturer, importer, or distributor.
- Any framework or customer requirement that prompted you to look.
Please keep a first message free of confidential technical detail and trade secrets. Once we reply we can agree an encrypted channel for anything sensitive.