New CRAcademy Resource – The CRA Compliance Glossary

28 Jul, 2026
CRA Compliance Glossary

Understanding the Cyber Resilience Act (CRA) starts with understanding its language and that language isn’t always easy to navigate. Legal terminology, technical acronyms, and compliance concepts are scattered across the regulation and its supporting standards, often without a clear, accessible explanation in one place.

To close that gap, CRACoWi partners have developed the CRA Compliance Glossary, now available as a new resource on the CRAcademy hub. Built as part of CRAcademy’s mission to provide clear and practical information about the CRA (through FAQs, blogs, expert insights, and more) the glossary is designed to be your quick reference whenever CRA terminology gets in the way of getting things done.

The Glossary

The glossary brings together plain-language definitions of the terms, acronyms, and concepts that come up throughout the CRA compliance journey — from foundational security properties like confidentiality, integrity, and availability, to CRA-specific mechanisms such as the Declaration of Conformity, CE marking, and conformity assessment routes. It also covers the technical vocabulary manufacturers and product teams encounter in practice: SBOMs, SAST/DAST testing, threat modelling frameworks like STRIDE, vulnerability disclosure policies, and more.

Each entry is written to be understood without a legal or cybersecurity background, while staying precise enough to be useful for teams already deep in their compliance work.

The Cyber Resilience Act establishes uniform cybersecurity criteria for digital products placed on the EU market, covering the entire product lifecycle from design through decommissioning. For manufacturers, importers, and distributors (particularly SMEs without dedicated legal or cybersecurity teams) getting familiar with this vocabulary is often the first practical step toward compliance, well before documentation or technical measures come into play.

Available as a free PDF on Zenodo

For those who prefer to save, print, or share the glossary offline, a PDF version of the CRA Compliance Glossary has also been published as an open-access download on Zenodo, ensuring the resource remains freely and permanently available to the wider CRA compliance community.

Part of a growing CRAcademy toolkit

The glossary joins the CRAcademy webinar series and other capacity-building resources already available on the platform, reinforcing CRACoWi’s broader goal: helping SMEs, manufacturers, distributors, and importers meet new cybersecurity standards throughout the product lifecycle.

You may also like

Event: Building Cyber Resilience in the Digital Era   

Event: Building Cyber Resilience in the Digital Era

A joint workshop on NIS2 compliance, CRA enforcement, and cross-border cybersecurity incident response. 📅 Friday, 2 October 2026 🕘 09:00 – 16:00 📍 Electra Palace Athens - 18-20 N. Nikodimou str, 10557 Athens, Greece 🌐 Language: EnglishThe EU cybersecurity regulatory...