{"id":71112,"date":"2026-09-08T18:57:51","date_gmt":"2026-09-08T18:57:51","guid":{"rendered":"https:\/\/www.oxfordcorp.com\/?p=71112"},"modified":"2026-09-08T18:59:51","modified_gmt":"2026-09-08T18:59:51","slug":"how-businesses-can-prepare-for-cra-regulations-in-europe","status":"publish","type":"post","link":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/","title":{"rendered":"How Businesses Can Prepare for CRA Regulations in Europe\u00a0"},"content":{"rendered":"<p><span data-contrast=\"auto\">The <\/span><a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/library\/commission-publishes-new-guidance-support-timely-cyber-resilience-act-implementation\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">European Commission&#8217;s June 2026 guidance<\/span><\/a><span data-contrast=\"auto\"> confirmed the EU Cyber Resilience Act (Regulation (EU) 2024\/2847) has moved from policy ambition to operational reality. Vulnerability and incident reporting obligations under Article 14 take effect on <\/span><b><span data-contrast=\"auto\">September 11, 2026<\/span><\/b><span data-contrast=\"auto\">, with the full set of essential requirements, including secure-by-design controls, technical documentation, conformity assessment, and CE marking, applying from <\/span><b><span data-contrast=\"auto\">December 11, 2027<\/span><\/b><span data-contrast=\"auto\">. Any company placing digital products on the EU market must now convert CRA requirements into working product security programs, defensible evidence, and governance that can hold up under regulatory scrutiny.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The urgency is compounded by a more hostile threat environment. <\/span><a href=\"https:\/\/www.enisa.europa.eu\/sites\/default\/files\/2025-10\/ENISA%20Threat%20Landscape%202025%20Booklet.pdf\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">ENISA&#8217;s 2025 incident analysis<\/span><\/a><span data-contrast=\"auto\"> points to faster vulnerability exploitation, professionalized cybercrime, automated social engineering, and persistent software supply chain risk. For manufacturers, importers, and distributors, CRA readiness proves that security is engineered in from architecture through post-market monitoring (and not bolted on) before an audit.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Why Readiness Can&#8217;t Wait<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">The compliance timeline rewards early movers and penalizes late ones, meaning companies cannot wait to build readiness. Before the broader 2027 deadline, manufacturers need functioning vulnerability intake, triage, product-impact analysis, and reporting workflows for actively exploited vulnerabilities and severe incidents. Reports must reach ENISA and the relevant national CSIRT through the <\/span><a href=\"https:\/\/www.enisa.europa.eu\/topics\/product-security\/single-reporting-platform-srp\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">CRA Single Reporting Platform<\/span><\/a><span data-contrast=\"auto\">. An early warning must be received within 24 hours of awareness, and a full notification within 72 hours.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Software supply chain research reinforces the urgency. Reviews of software bill of materials (SBOM) practice consistently find that <\/span><a href=\"https:\/\/arxiv.org\/abs\/2506.03507\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">SBOMs strengthen supply chain assurance<\/span><\/a><span data-contrast=\"auto\"> only when the underlying tooling\u00a0 produces reliable, decision-ready evidence; not just a compliance artifact filed away after release.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Confirm Which Products Are in Scope<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Scoping is the first real technical step. Companies should inventory every product with digital elements sold, imported, or distributed in the EU, identify which entity holds the &#8220;manufacturer&#8221; role under the CRA for each one, and flag product variants or configurations that could shift classification or obligations.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">IoT and connected-product environments deserve particular scrutiny. As reflected in a <\/span><a href=\"https:\/\/www.mdpi.com\/1999-5903\/17\/1\/30\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">2025 survey in Future Internet<\/span><\/a><span data-contrast=\"auto\">, heterogeneous devices, distributed networks, pervasive connectivity, and resource-constrained endpoints all complicate scope decisions. In these environments, scoping is an architectural risk exercise, not a spreadsheet inventory task.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Map Obligations to the Product Portfolio<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Once scope is set, businesses need a product cyber resilience inventory that translates regulatory language into traceable, product-level evidence: risk classification, vulnerability response ownership, conformity pathway, and the documentation needed to answer customer or regulator questions.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Classification then determines the applicable compliance route (i.e., default, important, or critical category). Each path should tie back to a concrete evidence set proving the relevant requirements were engineered into the product, not asserted after the fact.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Build Security by Design Into Engineering<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">CRA readiness is ultimately an engineering discipline rather than a compliance checklist. Secure-by-design engineering practices need to be part of standard development workflows and tailored to each product&#8217;s use case, environment, and exposure profile, not added late as a pre-release gate. These controls include:<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Threat modeling<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Secure coding standards<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Dependency review<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Application security testing<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Secrets management<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Vulnerability scanning<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Penetration testing<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Release gates<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">Secure-by-design also means secure defaults: minimized attack surfaces, least-privilege access, strong authentication and authorization, data protection, integrity validation where relevant, and update delivery through protected channels. Connected and embedded products should be tested specifically against misuse scenarios, including compromised credentials, exposed interfaces, supply chain manipulation, insecure configuration, and failed updates.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Design intent isn&#8217;t enough on its own. Organizations need to preserve product security evidence (e.g., requirements, design records, test results, code review artifacts, remediation logs, release approvals, and monitoring data) to show that controls were implemented, verified, and maintained over time, not just specified.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Strengthen Vulnerability Management and Reporting<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Because reporting obligations start first, vulnerability response deserves priority investment now. That means a coordinated disclosure process with clear incident and vulnerability handling procedures and named owners for each step. Meeting the 24-hour and 72-hour windows requires this to already be running, not designed under deadline pressure.\u00a0<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">A<\/span><span data-contrast=\"auto\">utomation can help (vulnerability intelligence feeds, CVE monitoring, SBOM matching, VEX status tracking, reachability analysis, and incident escalation should work together), but accuracy matters as much as speed. Research on SBOM-based vulnerability management found that <\/span><a href=\"https:\/\/arxiv.org\/abs\/2511.20313\" target=\"_blank\" rel=\"noopener\"><span data-contrast=\"none\">downstream vulnerability scanners produced a 92.0% false-positive rate<\/span><\/a><span data-contrast=\"auto\"> in a study of 2,414 open-source repositories, largely because alerts included vulnerabilities in unreachable code; function-call analysis reduced those false alarms by 61.9%. In short, tooling that floods triage teams with noise will slow reporting rather than speed it up.<\/span><span data-ccp-props=\"{}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Get Documentation and Evidence in Order<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Technical documentation is where CRA readiness becomes demonstrable rather than aspirational. Businesses need a structured evidence file connecting:<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Risk assessments<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Product architecture<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Software and firmware composition<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Secure development controls<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Vulnerability handling records<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Test results<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Conformity rationale<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">User security instructions<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">SBOMs should be treated as living engineering artifacts, not static compliance attachments: machine-readable, version-controlled, regenerated at every release, linked to build pipelines, and mapped to vulnerability intelligence, supplier data, and deployment artifacts. SBOM quality varies significantly depending on the generation tool and method used, so documented quality checks and repeatable generation processes matter. An SBOM that can&#8217;t be trusted is worse than no SBOM at all.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Documentation should also cover lifecycle security and support governance. Without assigned ownership, compliance knowledge fragments across teams and becomes unusable exactly when it&#8217;s needed most.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Assess Conformity and CE Marking<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">Conformity assessment is where cybersecurity work connects to market access. Organizations should determine the applicable route for each product based on classification, risk category, and intended use (i.e., default, important, or critical).<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">The most effective approach translates CRA requirements into testable product controls. For instance, secure update obligations should map directly to update architecture, code signing, rollback controls, integrity checks, and other assurance controls.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">CE marking should be treated as the output of an ongoing assurance process rather than a one-time administrative milestone. The supporting evidence file, including risk analysis, test results, conformity rationale, post-market monitoring plans, and more, needs to stay current as products evolve.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Extend Readiness to Suppliers and Partners<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">CRA obligations don&#8217;t stop at the company&#8217;s own code. Many digital products depend on a broad connected supply chain or third-party technology ecosystem, so supplier contracts, procurement standards, and open-source governance policies need to clearly assign lifecycle cybersecurity responsibilities.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">When a third-party issue affects an EU-market product, supplier requirements should include:<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><span data-contrast=\"auto\">Machine-readable SBOMs<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Component provenance<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Vulnerability disclosure commitments<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Patch timelines<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Secure development attestations<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><span data-contrast=\"auto\">Clear notification obligations<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">VEX records or equivalent exploitability documentation help separate theoretical component exposure from actual product-relevant risk, reducing noise and supporting more defensible reporting decisions.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Build a Phased Roadmap<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">A phased approach turns CRA complexity into an executable program:<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><b><span data-contrast=\"auto\">Near term (before September 2026):<\/span><\/b><span data-contrast=\"auto\"> Complete scoping, assign accountable owners, establish cross-functional governance, close tooling gaps, and test reporting workflows end to end.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Mid term:<\/span><\/b><span data-contrast=\"auto\"> Mature the technical foundation by embedding secure-by-design controls, improving SBOM generation and validation, integrating vulnerability intelligence, updating supplier contracts, and assembling conformity evidence packages.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">After December 2027:<\/span><\/b><span data-contrast=\"auto\"> Update documentation at every release, refresh threat models when architecture changes, run periodic audits, monitor supplier performance, and maintain continuous post-market vulnerability surveillance.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Turn Compliance Into Competitive Advantage<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">For companies that act early, CRA compliance can become more than a regulatory obligation. It can strengthen product security, improve software supply chain visibility, accelerate vulnerability response, and build customer confidence in a more closely scrutinized EU market. The organizations best positioned for the CRA will treat readiness as an engineering discipline, not a filing exercise, by building an integrated cyber resilience operating model that makes security assurance continuous, evidence-driven, and defensible.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Building that model takes specialized expertise. At Oxford, we connect businesses with the talent needed to turn a CRA roadmap into a functioning program. Because readiness rarely fits neatly into one role, we can help close gaps across conformity assessment, technical documentation, supplier governance, and post-market monitoring. Our consultants can support targeted projects, embed within existing teams, or help build a permanent security function as requirements mature.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Whether your business needs one expert to close a critical gap or a broader team to stand up an evidence-driven security program, we are ready to help.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Frequently Asked Questions About CRA Readiness<\/span><span data-ccp-props=\"{&quot;134245418&quot;:true,&quot;134245529&quot;:true,&quot;335559738&quot;:160,&quot;335559739&quot;:80}\">\u00a0<\/span><\/h2>\n<h3><span data-contrast=\"none\">What is the EU Cyber Resilience Act?<\/span><\/h3>\n<p><span data-contrast=\"auto\">The EU Cyber Resilience Act is a cybersecurity regulation for products with digital elements placed on the EU market. It requires companies to build security into products, maintain technical documentation, manage vulnerabilities, and provide evidence that products meet applicable requirements.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span data-contrast=\"none\">When do CRA requirements take effect?<\/span><\/h3>\n<p><span data-contrast=\"auto\">Vulnerability and incident reporting obligations begin on September 11, 2026. The broader requirements, including secure-by-design controls, technical documentation, conformity assessment, and CE marking, apply from December 11, 2027.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span data-contrast=\"none\">Which businesses need to prepare for the CRA?<\/span><\/h3>\n<p><span data-contrast=\"auto\">Any manufacturer, importer, or distributor placing digital products on the EU market should assess whether its products are in scope. This includes connected devices, software-enabled products, embedded systems, and products that rely on third-party or open-source components.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span data-contrast=\"none\">What should businesses do first?<\/span><\/h3>\n<p><span data-contrast=\"auto\">Companies should start by confirming which products are in scope, assigning accountable owners, and testing vulnerability reporting workflows. Early readiness work should also include SBOM quality, supplier governance, and evidence collection.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h3><span data-contrast=\"none\">How can Oxford help with CRA readiness?<\/span><\/h3>\n<p><span data-contrast=\"auto\">Oxford offers three flexible engagement models \u2014 staff augmentation, co-managed, and fully managed delivery \u2014 so you can choose how much of the program to own, from closing a single gap to running full execution across scoping, conformity assessment, documentation, supplier governance, vulnerability management, and post-market monitoring.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<h2 aria-level=\"2\"><span data-contrast=\"none\">Where Oxford Fits In<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;134245418&quot;:false,&quot;134245529&quot;:false,&quot;201341983&quot;:0,&quot;335559738&quot;:160,&quot;335559739&quot;:80,&quot;335559740&quot;:240}\">\u00a0<\/span><\/h2>\n<p><span data-contrast=\"auto\">CRA readiness rarely fits a single delivery model, so <\/span><a href=\"https:\/\/www.oxfordcorp.com\/services\/\"><span data-contrast=\"none\">we offer three flexible ways to engage<\/span><\/a><span data-contrast=\"auto\">, depending on how much of the program you want to own. Whether you need one specialist to close a single gap or a fully managed team running the program end-to-end, we scale with you as requirements evolve.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p><span data-contrast=\"auto\">Across all three models, we draw on deep bench strength spanning the full range of CRA disciplines:<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<ul>\n<li><b><span data-contrast=\"auto\">Engineering and product security:<\/span><\/b><span data-contrast=\"auto\"> Product Security, Secure Coding\/AppSec, Embedded\/Firmware Security, DevSecOps, and Penetration Testing<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Documentation and conformity:<\/span><\/b><span data-contrast=\"auto\"> CRA Compliance, Technical Documentation, Conformity Assessment, and Regulatory Affairs<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Vulnerability management:<\/span><\/b><span data-contrast=\"auto\"> Vulnerability Management, Incident Response, and SBOM\/Supply Chain Risk<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<li><b><span data-contrast=\"auto\">Governance and leadership:<\/span><\/b><span data-contrast=\"auto\"> CRA Program Management, GRC, and Third-Party Risk\/Vendor Security Auditing<\/span><span data-ccp-props=\"{&quot;201341983&quot;:0,&quot;335559739&quot;:0,&quot;335559740&quot;:240}\">\u00a0<\/span><\/li>\n<\/ul>\n<p><span data-contrast=\"auto\">If you&#8217;re working out where your CRA program has gaps, we&#8217;re here to talk through it.<\/span><span data-ccp-props=\"{&quot;134233279&quot;:true,&quot;201341983&quot;:0,&quot;335559738&quot;:240,&quot;335559739&quot;:240,&quot;335559740&quot;:240}\">\u00a0<\/span><\/p>\n<p>&nbsp;<br \/>\n&nbsp;<\/p>\n<div style=\"text-align: center;\">\n<p>     <a href=\"https:\/\/www.oxfordcorp.com\/contact\/?utm_source=Insights&#038;utm_medium=CTA_Click&#038;utm_campaign=CTA#i'm-looking-for-talent\" style=\"display: inline-block; padding: 10px 20px; background-color: #FFD300; color: #000; font-weight: bold; text-decoration: none; border-radius: 4px; box-shadow: 0px 3px 5px rgba(0, 0, 0, 0.2); transition: background-color 0.3s ease;\">CONNECT WITH OXFORD &rarr;<\/a>  <\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>The EU Cyber Resilience Act is now in force. See what manufacturers and distributors need for CRA-ready product security before deadlines hit.<\/p>\n","protected":false},"author":22,"featured_media":71113,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[183],"tags":[],"category-tag":[],"class_list":["post-71112","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.3 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>How Businesses Can Prepare for CRA Regulations in Europe\u00a0 - Oxford Global Resources<\/title>\n<meta name=\"description\" content=\"The EU Cyber Resilience Act is now in force. See what manufacturers and distributors need for CRA-ready product security before deadlines hit.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.oxfordcorp.com\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/\" \/>\n<meta property=\"og:locale\" content=\"nl_NL\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Businesses Can Prepare for CRA Regulations in Europe\u00a0\" \/>\n<meta property=\"og:description\" content=\"The EU Cyber Resilience Act is now in force. See what manufacturers and distributors need for CRA-ready product security before deadlines hit.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/\" \/>\n<meta property=\"og:site_name\" content=\"Oxford Global Resources\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-08T18:57:51+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-08T18:59:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.oxfordcorp.com\/wp-content\/uploads\/2026\/09\/Insights-Website-Graphics-1920-X-1080-23.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"kcompton\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Geschreven door\" \/>\n\t<meta name=\"twitter:data1\" content=\"kcompton\" \/>\n\t<meta name=\"twitter:label2\" content=\"Geschatte leestijd\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minuten\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/\"},\"author\":{\"name\":\"kcompton\",\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/#\\\/schema\\\/person\\\/42927b5e78a84b0692a4221cdc55bad5\"},\"headline\":\"How Businesses Can Prepare for CRA Regulations in Europe\u00a0\",\"datePublished\":\"2026-09-08T18:57:51+00:00\",\"dateModified\":\"2026-09-08T18:59:51+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/\"},\"wordCount\":1707,\"image\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.oxfordcorp.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Insights-Website-Graphics-1920-X-1080-23.jpg\",\"articleSection\":[\"Blog\"],\"inLanguage\":\"nl-NL\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/\",\"url\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/\",\"name\":\"How Businesses Can Prepare for CRA Regulations in Europe\u00a0 - Oxford Global Resources\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.oxfordcorp.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Insights-Website-Graphics-1920-X-1080-23.jpg\",\"datePublished\":\"2026-09-08T18:57:51+00:00\",\"dateModified\":\"2026-09-08T18:59:51+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/#\\\/schema\\\/person\\\/42927b5e78a84b0692a4221cdc55bad5\"},\"description\":\"The EU Cyber Resilience Act is now in force. See what manufacturers and distributors need for CRA-ready product security before deadlines hit.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/#breadcrumb\"},\"inLanguage\":\"nl-NL\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"nl-NL\",\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.oxfordcorp.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Insights-Website-Graphics-1920-X-1080-23.jpg\",\"contentUrl\":\"https:\\\/\\\/www.oxfordcorp.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Insights-Website-Graphics-1920-X-1080-23.jpg\",\"width\":1600,\"height\":900,\"caption\":\"Gavel resting beside a lawyer's hands writing legal documents, symbolizing EU Cyber Resilience Act compliance preparation.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/blog\\\/how-businesses-can-prepare-for-cra-regulations-in-europe\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Businesses Can Prepare for CRA Regulations in Europe\u00a0\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/#website\",\"url\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/\",\"name\":\"Oxford Global Resources\",\"description\":\"Global\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"nl-NL\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/#\\\/schema\\\/person\\\/42927b5e78a84b0692a4221cdc55bad5\",\"name\":\"kcompton\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"nl-NL\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2cd530781db51f88a48fa8c72240ebb3cd8fb42b119eeb9a6f6765b5764705cc?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2cd530781db51f88a48fa8c72240ebb3cd8fb42b119eeb9a6f6765b5764705cc?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/2cd530781db51f88a48fa8c72240ebb3cd8fb42b119eeb9a6f6765b5764705cc?s=96&d=mm&r=g\",\"caption\":\"kcompton\"},\"url\":\"https:\\\/\\\/www.oxfordcorp.com\\\/nl\\\/insights\\\/author\\\/kcompton\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"How Businesses Can Prepare for CRA Regulations in Europe\u00a0 - Oxford Global Resources","description":"The EU Cyber Resilience Act is now in force. See what manufacturers and distributors need for CRA-ready product security before deadlines hit.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.oxfordcorp.com\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/","og_locale":"nl_NL","og_type":"article","og_title":"How Businesses Can Prepare for CRA Regulations in Europe\u00a0","og_description":"The EU Cyber Resilience Act is now in force. See what manufacturers and distributors need for CRA-ready product security before deadlines hit.","og_url":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/","og_site_name":"Oxford Global Resources","article_published_time":"2026-09-08T18:57:51+00:00","article_modified_time":"2026-09-08T18:59:51+00:00","og_image":[{"width":1600,"height":900,"url":"https:\/\/www.oxfordcorp.com\/wp-content\/uploads\/2026\/09\/Insights-Website-Graphics-1920-X-1080-23.jpg","type":"image\/jpeg"}],"author":"kcompton","twitter_card":"summary_large_image","twitter_misc":{"Geschreven door":"kcompton","Geschatte leestijd":"8 minuten"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/#article","isPartOf":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/"},"author":{"name":"kcompton","@id":"https:\/\/www.oxfordcorp.com\/nl\/#\/schema\/person\/42927b5e78a84b0692a4221cdc55bad5"},"headline":"How Businesses Can Prepare for CRA Regulations in Europe\u00a0","datePublished":"2026-09-08T18:57:51+00:00","dateModified":"2026-09-08T18:59:51+00:00","mainEntityOfPage":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/"},"wordCount":1707,"image":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/#primaryimage"},"thumbnailUrl":"https:\/\/www.oxfordcorp.com\/wp-content\/uploads\/2026\/09\/Insights-Website-Graphics-1920-X-1080-23.jpg","articleSection":["Blog"],"inLanguage":"nl-NL"},{"@type":"WebPage","@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/","url":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/","name":"How Businesses Can Prepare for CRA Regulations in Europe\u00a0 - Oxford Global Resources","isPartOf":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/#primaryimage"},"image":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/#primaryimage"},"thumbnailUrl":"https:\/\/www.oxfordcorp.com\/wp-content\/uploads\/2026\/09\/Insights-Website-Graphics-1920-X-1080-23.jpg","datePublished":"2026-09-08T18:57:51+00:00","dateModified":"2026-09-08T18:59:51+00:00","author":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/#\/schema\/person\/42927b5e78a84b0692a4221cdc55bad5"},"description":"The EU Cyber Resilience Act is now in force. See what manufacturers and distributors need for CRA-ready product security before deadlines hit.","breadcrumb":{"@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/#breadcrumb"},"inLanguage":"nl-NL","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/"]}]},{"@type":"ImageObject","inLanguage":"nl-NL","@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/#primaryimage","url":"https:\/\/www.oxfordcorp.com\/wp-content\/uploads\/2026\/09\/Insights-Website-Graphics-1920-X-1080-23.jpg","contentUrl":"https:\/\/www.oxfordcorp.com\/wp-content\/uploads\/2026\/09\/Insights-Website-Graphics-1920-X-1080-23.jpg","width":1600,"height":900,"caption":"Gavel resting beside a lawyer's hands writing legal documents, symbolizing EU Cyber Resilience Act compliance preparation."},{"@type":"BreadcrumbList","@id":"https:\/\/www.oxfordcorp.com\/nl\/insights\/blog\/how-businesses-can-prepare-for-cra-regulations-in-europe\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.oxfordcorp.com\/nl\/"},{"@type":"ListItem","position":2,"name":"How Businesses Can Prepare for CRA Regulations in Europe\u00a0"}]},{"@type":"WebSite","@id":"https:\/\/www.oxfordcorp.com\/nl\/#website","url":"https:\/\/www.oxfordcorp.com\/nl\/","name":"Oxford Global Resources","description":"Global","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.oxfordcorp.com\/nl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"nl-NL"},{"@type":"Person","@id":"https:\/\/www.oxfordcorp.com\/nl\/#\/schema\/person\/42927b5e78a84b0692a4221cdc55bad5","name":"kcompton","image":{"@type":"ImageObject","inLanguage":"nl-NL","@id":"https:\/\/secure.gravatar.com\/avatar\/2cd530781db51f88a48fa8c72240ebb3cd8fb42b119eeb9a6f6765b5764705cc?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/2cd530781db51f88a48fa8c72240ebb3cd8fb42b119eeb9a6f6765b5764705cc?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/2cd530781db51f88a48fa8c72240ebb3cd8fb42b119eeb9a6f6765b5764705cc?s=96&d=mm&r=g","caption":"kcompton"},"url":"https:\/\/www.oxfordcorp.com\/nl\/insights\/author\/kcompton\/"}]}},"_links":{"self":[{"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/posts\/71112","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/users\/22"}],"replies":[{"embeddable":true,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/comments?post=71112"}],"version-history":[{"count":2,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/posts\/71112\/revisions"}],"predecessor-version":[{"id":71121,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/posts\/71112\/revisions\/71121"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/media\/71113"}],"wp:attachment":[{"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/media?parent=71112"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/categories?post=71112"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/tags?post=71112"},{"taxonomy":"category-tag","embeddable":true,"href":"https:\/\/www.oxfordcorp.com\/nl\/wp-json\/wp\/v2\/category-tag?post=71112"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}