The Cyber Resilience Act (CRA)
You, as a manufacturer of Products with Digital Elements (PwDE) within the CRA scope, are fully aware that your PwDE must comply with the CRA by the …
The Standardization Request M/606 has been referenced several times in the blog. But what is it? That is the topic for this …
Is the upcoming CRA-aligned EN IEC 62443/A11 harmonized standard up to the task of protecting against AI-driven attacks, or has it already been …
CRA Article 27 establishes the legal framework and mechanisms by which products with digital elements (and their manufacturers’ processes) can obtain a Presumption of …
The (still-in-draft) Commission guidance on the Cyber Resilience Act assists economic operators (with a particular focus on microenterprises and SMEs) and market …
Various forms of CRA assistance are available. This article is the first in a series outlining the available help. The biggest help, …
Here you’ll find a condensed executive summary of the Cyber Resilience Act, what it is, and the key criteria for compliance. You …
A WTG (Wind Turbine Generator) manufacturer asks a supplier to design a sub-component in accordance with its specifications. How is the CRA …
The Cyber Resilience Act is just another expected-to-be-delayed NIS2 variant, right? No! You may recall that NIS2 is a Directive, whereas CRA is a Regulation. …
I’ve created an online tool to help my customers get an overview of and apply the Security Evaluation Methodology in EN IEC …
What does it, seen from an EN IEC 62443-4-1:2018/A11:2026 auditor’s point of view, take to cross the finishing line? You know it …
This article takes a closer look at the forthcoming (not yet cited in OJEU) EN IEC 62443-4-1:2018/A11:2026© harmonized standard. The primary objective of …
This article explores the vertical standard ETSI EN 304 633© for internet-connected toys and the CRA presumption of conformity. While currently in …
We’ll take a closer look at the technical and structural changes introduced in the coming EN IEC 62443-4-2/A11©. The A11 amendment represents the …
This article explores the CRA standards sandwich and specifically where EN IEC 62443/A11 fits. The citation of EN IEC 62443/A11 in the …
We’re taking a sneak-peek under the hood of the coming EN 40000-1-x family of harmonized horizontal standards using a hypothetical smart-home thermostat …
Understand how the horizontal standards (EN 40000‑1‑x family) relate to the presumption of conformity under the CRA Regulation (EU) 2024/2847, what the …
This is the first in a series of articles on the Cyber Resilience Act (CRA). The rationale behind CRA The Cyber Resilience …
Governance, Risk & Compliance (GRC)
Artiklerne GRC and Third-Party Risk Management og ISMS Cookbook omhandler begge vinkler på GRC og adresserer i nogen grad GDPR. Fokus i denne artikel og …
This article focuses on outbound GRC (Governance, Risk, and Compliance) cybersecurity for third parties, in contrast to the inbound ISMS Unified Control Framework. …
The original intention of this article was to provide guidance on structuring the “normal” ISO 27001 ISMS. Then reality hit. The ISMS cannot …
Regulation (EU) 2024/1689 [EU AI Act] establishes a uniform, risk-based legal framework to ensure trustworthy AI throughout the European Union while safeguarding …
In the quest to help organizations approach ISO 27001, I’ve added an ISO 27001 Internal Audit Guide to the toolbox. Because it closely aligns …
Based on publicly available information about ITIL 5, I’ve created, supported by AI, an interactive guide to bring you up to speed in …
CER-loven (Lov om kritiske enheders modstandsdygtighed) er en relativt ny dansk lov, der har til formål at sikre, at samfundskritiske virksomheder og …
OPDATERING 29-7-2026: Det interaktive NIS2-auditværktøj er opdateret, og der er nu også en interaktiv guide til at navigere i NIS2-loven. OPDATERING 15-8-2026: Det interaktive …
Formålet med denne artikel er at hjælpe danske forsyningsselskaber med at implementere og dokumentere kravene i Lov om styrket beredskab i energisektoren …
The Product Operating Model (POM)
You might have read my lengthy articles on the Product Operating Model. Here is a consolidated recap as an interactive guide. For …
Each of the core ingredients for a successful product organization is a deep rabbit hole in its own right. This article intentionally …
My earlier article on product delivery recommended the core strategy of implementing Continuous Delivery as described by Dave Farley. To recap, Continuous …
This is the fourth in the series of articles on the product operating model. To recap, it has three dimensions. The right …
This is the third in the series of articles on the product operating model. To recap, it has three dimensions. The right …
This is the second in a series of articles on the product operating model. To recap, it has three dimensions. The right …
This is the first in a series of articles on the product operating model. It’ll be a mix of my practical experience …
Let’s Turn Strategy Into Delivered Value
Whether you are navigating CRA and NIS2 conformity, transitioning toward an empowered Product Operating Model, or de-risking a mission-critical technology project, let’s explore how we can work together.
