The CRAIR blog

The Cyber Resilience Act, SBOMs, and staying audit-ready. Written for small EU software vendors. RSS feed

Small companies and CRA fines: the exemption most write-ups miss

I told small software vendors they'd face €15M CRA fines. A standardisation expert corrected me: micro and small enterprises are exempt from fines for missing the 24-hour deadline. Here's the accurate picture, and why readiness still matters.

8 Aug 2026 · 4 min read

SBOM, in plain English

SBOM is one of those acronyms that sounds more technical than it is. Here's what a Software Bill of Materials actually is, and why people suddenly want yours.

19 Jul 2026 · 2 min read