Compliance

cyber resilience act vulnerability handling requirements a upright funnel

Vulnerability Handling Requirements: Proven Safe CRA Guide

A plain-language walkthrough of the vulnerability handling requirements in Annex I, Part II of the EU Cyber Resilience Act for software teams: the eight duties from SBOM documentation to free security updates, how the five-year support period stretches them across a product’s life, what a coordinated vulnerability disclosure policy must contain, how the handling process feeds the 24-hour and 72-hour Article 14 reporting clocks from September 2026, the fine bands up to 15 million euros, the mistakes that fail assessments, and a 90-day plan to stand the whole process up before the December 2027 deadline.

Read more
sbom requirements eu cyber resilience act a tall stack blank paper sheets

SBOM Requirements: Essential EU CRA Guide to Avoid Risk

A deep-dive on SBOM requirements under the EU Cyber Resilience Act for software teams: what Annex I, Part II actually obliges you to document, the seven minimum data fields every component entry needs, how to choose between SPDX and CycloneDX, how to generate and store SBOMs in your delivery pipeline, keeping them current across versions and patches, the VEX workflow that makes vulnerability matching usable, what market surveillance authorities can demand, the fine bands up to €15 million, and a 90-day plan to get compliant before the December 2027 deadline.

Read more
cyber resilience act checklist software developers a clipboard with check marks

Cyber Resilience Act Checklist: Proven Steps to Avoid Fines

A working Cyber Resilience Act checklist for software developers and engineering leads. Six workstreams in delivery order: inventory and classification, the Annex I secure development requirements, machine-readable SBOMs with CycloneDX or SPDX, vulnerability handling that survives an audit, the 24-hour reporting capability due by 11 September 2026, and the technical file, declaration of conformity and CE marking due by 11 December 2027 — plus the fine bands, the 2026 Commission guidance, the draft harmonised standards, a 16-month plan and the mistakes development teams most often make.

Read more
cyber resilience act reporting requirements a three ascending rounded pillars

Cyber Resilience Act Reporting: Proven Guide to Avoid Fines

Cyber Resilience Act reporting becomes a live legal duty on 11 September 2026, fifteen months before the rest of Regulation (EU) 2024/2847 applies. This operational guide covers the two triggers that start the clock, what “becoming aware” means, the 24-hour early warning, the 72-hour notification and the 14-day or one-month final report, the ENISA single reporting platform and how to choose a coordinating CSIRT, what each submission must contain, who is authorised to file out of hours, the parallel duty to notify users, how the clocks interact with NIS2, DORA and UK GDPR, the evidence pack, the penalty bands, and a four-week readiness plan.

Read more
cyber resilience act compliance uk software companies a three ascending rounded pillars

Cyber Resilience Act Compliance: Essential UK Risk Guide

Cyber Resilience Act compliance stops being a 2027 problem on 11 September 2026, when the Article 14 reporting duties in Regulation (EU) 2024/2847 switch on and every UK software company selling into the European Union inherits a 24-hour clock. This guide explains which products with digital elements are caught, why a UK vendor is almost always the manufacturer, how the default, Class I, Class II and critical tiers change your conformity route, what the Annex I essential requirements mean in engineering terms, how the SBOM and vulnerability handling duties work, the five-year support period and ten-year update availability rules, the three reporting clocks, the penalty ceilings, and a twelve-month programme to reach a defensible position.

Read more
automated decision-making - automated decision making under the duaa a branching decision node

Automated Decision-Making: Essential DUAA Rules to Avoid Risk

Section 80 of the Data (Use and Access) Act 2025 deleted Article 22 of the UK GDPR and replaced it with Articles 22A to 22D, commenced on 5 February 2026. The prohibition became a permission with conditions: for ordinary personal data you may now make solely automated significant decisions, provided you notify the individual, accept representations, provide genuine human intervention and allow a contest. This guide sets out the two-part test, what the ICO now means by meaningful human involvement, the special category data rules that did not relax, where automated decisions hide inside ordinary business software, the EU divergence that catches exporters, the evidence pack a regulator will ask for, seven failure patterns and a 60-day plan.

Read more
duaa compliance checklist uk smes a upright grooved slab

DUAA Compliance: Essential SME Checklist to Avoid Costly Fines

The Data (Use and Access) Act 2025 is fully commenced and there is no small-business exemption from the parts that matter. This checklist is written for the firm with no data protection officer and one person watching the shared inbox: a three-question scoping test, the five-item baseline every UK controller must meet, the conditional duties that only fire for some businesses, the new universal complaints procedure and its 30-day clock, the cookie audit behind a PECR ceiling that rose from £500,000 to £17.5 million, automated decisions hiding inside off-the-shelf SaaS, an honest hour-and-cost budget, the nine-artefact evidence pack, seven small-business failure patterns, and a ninety-day plan with owners.

Read more
duaa uk gdpr changes what changed for businesses a three ascending rounded pillars

DUAA UK GDPR Changes: Essential Guide to Avoid Costly Risk

The Data (Use and Access) Act 2025 edits UK data protection law rather than replacing it, which is why a summary is less useful than a diff. This guide sets the pre-2026 position beside the current one across lawful basis and the new Annex 1 recognised legitimate interests, the repeal of Article 22 and the safeguards in Articles 22A to 22D, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day clock, and the three narrow cookie exemptions behind a PECR ceiling that rose from £500,000 to £17.5 million. It then translates every change into the document you edit, the team that owns it, a 90-hour effort register, a UK-versus-EU divergence table, and a ninety-day plan.

Read more
data use and access act 2025 a three ascending rounded pillars

Data Use and Access Act 2025: Essential UK Risk Checklist

The main data protection provisions commenced on 5 February 2026, the mandatory complaints procedure followed on 19 June 2026, and the maximum PECR penalty rose thirty-five-fold to £17.5 million. This guide sets out exactly what is in force, what is still pending, and what each change obliges a UK business to do differently: the commencement timetable tied to its statutory instruments, recognised legitimate interests and the direct-marketing trap underneath them, the repeal of Article 22 and the new Articles 22A to 22D on automated decision-making, the reasonable-and-proportionate subject access standard, the universal complaints duty and its 30-day acknowledgement clock, the three narrow cookie exemptions and why the analytics one is narrower than it looks, renewed EU adequacy to December 2031, what the Act pointedly did not change, and a sequenced six-step remediation plan for the rest of 2026.

Read more
WCAG 2.2 checklist - wcag 2 2 checklist business websites a three ascending rounded pillars

WCAG 2.2 Checklist: Proven Fixes to Avoid Costly Failures

Most business websites fail accessibility not because the team does not care but because nobody ever turned the standard into a list of things to check on a Tuesday afternoon. This guide turns WCAG 2.2 into that list: what the 86 success criteria actually are, which 55 you must meet for Level AA, the nine criteria that are new in 2.2 and catch modern sites out, the UK legal position under the Equality Act and the European Accessibility Act, a one-day testing routine using free tools, realistic UK remediation costs from a £0 in-house pass to a £14,000 rebuild, a 90-day roadmap, the overlap with SEO, and the mistakes that produce a green dashboard on an unusable site.

Read more
CHAT