The EU Cyber Resilience Act (CRA) is changing what companies need to demonstrate about the security of their products. Secure development, vulnerability handling, software supply-chain transparency, and technical documentation are all central concerns. Reporting obligations for actively exploited vulnerabilities and severe security incidents have applied since 11 September 2026; the main obligations apply from 11 December 2027. European Commission