The gap between compliant and demonstrably compliant
The Cyber Resilience Act borrows its enforcement architecture from decades of EU product law: essential requirements, conformity assessment, a declaration, a CE mark, and market surveillance after launch. If that machinery is unfamiliar, the lesson on conformity assessment for high-risk AI systems covers the general shape, and it transfers.
What is worth attention here is the CRA-specific part, which is where teams lose time.
The reframe that matters: a conformity assessment does not ask whether your product is secure. It asks whether you can show, from records, that you determined what security this product needed and then built to that determination. A well-engineered product with no documented risk assessment fails. A modest product with a coherent, evidenced chain of reasoning passes.
Everything in this lesson is downstream of that. The modules differ in who checks the records. The documentation requirements define what the records are. Market surveillance is what happens when someone asks to see them.

