Blog
The Finite State Blog

Practical insights and articles from our SMEs to help product security teams cut triage noise, fix what matters faster, and deliver audit-ready proof to customers and regulators.

40 results

A dark automotive ECU control module with a glowing teal wireframe twin hovering above it, mostly aligned with the physical device below, illustrating the gap between a supplier's claimed component list and what's actually inside..
Compliance

Trust but Verify: A Practical Guide to Supplier SBOM Validation

Supplier SBOMs are often incomplete. Here's why manufacturers verify them against the actual binaries, and how that holds up under CRA, FDA, ISO 21434...

Doc McConnell
Doc McConnellJULY 13, 2026
Overhead view of a dense array of dark, unlit connected devices—PLCs, gateways, cameras, routers—linked by cables, with one device in the center glowing bright orange while every other device stays dim, representing a single reachable vulnerability flagged among many.
Compliance

EPSS and CRA Triage: What to Do When a Vulnerability Lands

Under the CRA, vulnerability triage is a risk-based, documented decision. See how EPSS and reachability show which CVEs warrant action and which can w...

Doc McConnell
Doc McConnellJULY 8, 2026
X-ray 3/4 view of a connected vehicle, the dark car body shown in shadow while its internal electronics — infotainment unit, telematics module, OBD-II dongle, and dashcam — glow orange and are revealed by scan line passing through the car.
Compliance & RegulationsCompliance

Cyber Resilience Act for Automotive Suppliers: The Car Is Exempt, but What's Inside Isn't

Most suppliers hear "automotive is exempt" and move on. The CRA carves out the finished vehicle, but a meaningful share of what they sell still falls ...

Doc McConnell
Doc McConnellJUNE 24, 2026
A lineup of connected devices — an industrial PLC, a network router, and a smart home IoT hub — on a dark reflective surface, each overlaid with a teal X-ray scan revealing the circuit boards inside, illustrating continuous security scanning for CRA compliance.
Compliance & Regulations

CRA Compliance Is Not a Checkbox. It's a Continuous Program.

Manufacturers tend to prepare for the EU Cyber Resilience Act (CRA) the way they'd prepare for an exam, something you study for, pass, and put behind ...

Doc McConnell
Doc McConnellJUNE 17, 2026
Large warehouse full of outdated IoT devices. Caption reads "Supported doesn't mean finished."
Compliance

CRA Flips the Timeline: Why Retroactive Vulnerability Management Is the Real Challenge

Most CRA prep focuses on new products. The harder obligation reaches back across everything you have already shipped—and the September 11, 2026, deadl...

Doc McConnell
Doc McConnellJUNE 10, 2026
Illustration of an hourglass labeled “Article 14” with golden sand flowing downward beside a transparent digital map of Europe. Glowing network connections and security icons overlay the map against a dark background with faint EU stars, symbolizing a regulatory compliance deadline.
Compliance

CRA Vulnerability Reporting: September 2026 is Around the Corner

Starting September 11, 2026, manufacturers must notify ENISA within 24 hours of an actively exploited vulnerability. Most don't have the four operatio...

Doc McConnell
Doc McConnellMAY 28, 2026
Understanding The EU CRA's SBOM & Technical Documentation Requirements
SBOM ManagementCompliance & Regulations

Understanding The EU CRA's SBOM & Technical Documentation Requirements

Ensure compliance with the EU Cyber Resilience Act. Learn how IoT manufacturers can streamline SBOM creation, updates, and documentation with expert t...

Doc McConnell
Doc McConnell MAY 21, 2026
A stack of five semi-transparent glass document panels fanned and layered on a dark reflective surface. The top panel is illuminated by a bright teal scanning light sweeping horizontally across it, revealing faint data grids and chart lines beneath. An amber-orange glow emanates from the base of the stack, reflecting warmly on the surface below. The background is deep near-black with sparse scattered light points. The overall mood is technical, precise, and cinematic.
Compliance & Regulations

CRA Compliance Is a Full-Time Job. Most Teams Don't Have That.

EU CRA reporting obligations start in September 2026. Finite State's managed CRA service delivers five maintained compliance outputs for a designated ...

Finite State Team
Finite State TeamMAY 4, 2026
 IoT and the EU CRA: A Secure by Design Guide for Manufacturers
IoT & OTCompliance & Regulations

Secure by Design for IoT: The EU CRA Compliance Guide

Learn more about the EU Cyber Resilience Act’s Security by Design requirements and how to comply as an IoT manufacturer in this short guide.

Doc McConnell
Doc McConnell JANUARY 29, 2026
A Unified Path to CRA Compliance: Breaking Silos, Matching Risk
Compliance & Regulations

A Unified Path to CRA Compliance: Why Teams Need to Break Silos and Match Velocity

Learn how unified risk assessment and reachability help teams break silos, reduce CRA reporting effort, and focus on real, exploitable risk.

Dario Lobozzo
Dario LobozzoJANUARY 27, 2026
Cybersecurity Risk Assessments & The EU CRA
Product Security

Cybersecurity Risk Assessments & The EU CRA

How to run a CRA-ready cybersecurity risk assessment. The mandatory requirements, a step-by-step process, the tools, and how to keep it defensible acr...

Finite State Team
Finite State TeamJANUARY 24, 2026
EU CRA's Vulnerability Handling & Incident Reporting Rules: A Guide
Vulnerability ManagementCompliance & Regulations

CRA Vulnerability Management: Requirements, Deadlines & Tools

Navigate the EU Cyber Resilience Act's vulnerability handling & incident reporting requirements with part 2 of our guide for IoT manufacturers.

Doc McConnell
Doc McConnell JANUARY 15, 2026
Finite StateFinite State

Finite State is the Product Security Automation Platform that functions as an autonomous Product Security OS: design → verify → prove, grounded in what you ship.

Platform

Platform Overview
Ground Truth Inventory
Exploitability-Based Prioritization
Design-Time Architecture Security
Automated Evidence-Backed Compliance

Solutions

Device Manufacturers
Automotive
Medical Devices
Energy & Utilities
Government
Industrial

Resources

Blog
Resource Library
Webinars & Videos
Events
Documentation

Company

About Us
CareersHIRING
Press & News
Contact Sales
Media Inquiries
X

© 2026 Finite State. All rights reserved.

Privacy PolicyTerms of UseCustomer Terms and Conditions
Finite StateFinite State
Finite StateFinite State
Get a DemoGet a Demo