| Introduction and legal disclaimer
| Why the CRA is no longer a future problem
| What engineers need to do right now
| When the 24-hour reporting clock actually starts
| Legacy products and devices that cannot receive updates
| What changes when full compliance begins in December 2027
| How product classification changes the compliance process
| Creating a component inventory and SBOM/HBOM
| The five-year product-support obligation
| Handling vulnerabilities inherited from shared libraries
| Supporting products built on end-of-life dependencies
| Shipping AI-generated firmware under the CRA
| Are secure boot and signed updates mandatory?