Methodology

How we verify

Compliance tooling is only worth money if it is right. This page shows the discipline behind every claim on this site and in the CRA Blueprint, so you can judge it instead of trusting it.

One source of truth

Every regulatory claim we publish cites the provision of Regulation (EU) 2024/2847 (the EU Cyber Resilience Act) it rests on: the article, recital, or annex point. We verify against the Official Journal text itself, not summaries, blog posts, or other people's interpretations. In the Scope Checker, every question and every verdict carries its citation, and our test suite fails the build if any claim cites a provision that is not on the reviewed allowlist. The same rule binds the Knowledge Base guides and every document in the Blueprint.

Adversarial review before anything ships

A first draft is never trusted. Everything regulatory goes through at least one independent review pass whose only job is to check each claim against the Official Journal text and try to refute it. This is not theater: the process has caught real errors before publication, including a reporting deadline wrongly applied to importers and distributors, deadline clocks anchored to the wrong starting event, and product-category lists that silently dropped annex limbs (hardware security modules, children's wearables). Each of those was found by review and fixed before it could mislead anyone.

Judgment calls are labeled as judgment calls

Parts of the CRA are genuinely unsettled: when the open-source steward reporting duty starts, where the monetisation line falls for open-source projects, how the remote data processing test applies to a close case. Where the law does not settle a question, we say so in the product, explain the readings, and take the prudent default rather than pretending certainty. If you see a "judgment call" note on this site, that is the system working.

Kept current, with receipts

The CRA is still being built out: implementing acts, delegated acts, harmonised standards, and national designations keep landing. We re-verify time-sensitive claims against official sources and version every artifact. Blueprint buyers receive updated documents through the changelog, including the ENISA Single Reporting Platform walkthrough when the platform goes live on 11 September 2026 (Regulation (EU) 2024/2847, Article 71(2)).

Public changelog

  • 10 Jul 2026 Scope Checker shipped: every branch and verdict cited to the Official Journal text, verified in three independent review passes.
  • 12 Jul 2026 The checker's five open judgment calls re-verified independently; three product-category gaps found and fixed the same day (secure cryptoprocessing devices, children's wearables, biometric and access-control readers).
  • 17 Jul 2026 All five CRA Blueprint documents completed in audited draft; each one reviewed claim-by-claim against the Official Journal text, external facts checked against official sources.
  • 18 Jul 2026 CRA Knowledge Base published: 50 cited guides, each audited against the Official Journal text before going live.
  • 19 Jul 2026 Site redesign. No regulatory content changed; forms and citations verified unchanged.

Where this has limits

Vexwatch provides compliance tooling, not legal advice, and this methodology does not replace a qualified lawyer on your specific situation. A few facts can only be confirmed when institutions act: the Dutch coordinator designation, for example, sits in an implementing act still moving through the legislature, and our documents mark exactly those points as "confirm at go-live" instead of asserting them early. If you find a claim we got wrong, tell us: hello@vexwatch.com. We would rather fix it than defend it.

References to "the CRA" mean Regulation (EU) 2024/2847, the EU Cyber Resilience Act. Compliance tooling, not legal advice.