product-security
2 free lessons tagged product-security across Law & Compliance. Each one is a short sequence of focused steps with narration and a five-question quiz at the end — take them in any order, no signup required.
Annex I: The Product Properties and the Processes Behind Them
Annex I is two lists doing different jobs: thirteen properties the product must have, and eight things the manufacturer must keep doing. This lesson works through both, including the secure-by-default and automatic-update rules, what the software bill of materials clause actually demands, the five-year support period floor and the ten-year shelf life on each update, and what must reach the user.
The Cyber Resilience Act: What It Covers and Who It Binds
Regulation (EU) 2024/2847 puts software and connected hardware under product safety law, with a CE mark for cybersecurity. This lesson sets the scope: what counts as a product with digital elements, why a cloud backend can be part of one, what sector law carves out, where open source and stewards sit, the four risk tiers from Annex III and IV, and how a reseller becomes a manufacturer.

