CRA Desk

Cyber Resilience Act readiness checklist

Thirteen things the reporting obligation that started on 11 September 2026 asks of a software manufacturer. Each one names the unit of Regulation (EU) 2024/2847 it comes from, so you can check it against the act rather than against us. The CRA Desk scan answers the first four from your SBOM; the rest need a person.

  1. 1. A machine-readable SBOM exists for the product

    Annex I Part II(1) requires identifying and documenting components, including by drawing up an SBOM in a commonly used, machine-readable format. Without one, "which of our components is affected" has no answer inside 24 hours.

    What counts as evidence: A CycloneDX or SPDX JSON document produced by the build, stored per product version.

    Annex I, Part II, point 1checked automatically from your SBOM

  2. 2. Components carry package identifiers (purl)

    Matching a CVE to a component is only reliable against a package URL. Components identified by name alone are matched by heuristics, which produces both misses and false alarms.

    What counts as evidence: Every component in the SBOM has a purl.

    Annex I, Part II, point 1rests on practice, not on an operative provisionchecked automatically from your SBOM

  3. 3. Component versions are pinned in the SBOM

    A vulnerability applies to a version range. A component without a version cannot be judged affected or not, so it will be triaged by hand on the day it matters.

    What counts as evidence: Every component in the SBOM has a version.

    Annex I, Part II, point 1checked automatically from your SBOM

  4. 4. The SBOM records dependency relationships

    Annex I Part II(1) is read as covering at least top-level dependencies; a flat list cannot show whether a vulnerable package is one you ship directly or one pulled in transitively - which changes who has to fix it.

    What counts as evidence: CycloneDX `dependencies` or SPDX `relationships` are present.

    Annex I, Part II, point 1rests on practice, not on an operative provisionchecked automatically from your SBOM

  5. 5. The product’s CRA scope and class are established

    The reporting obligation applies to every product with digital elements in scope, whatever its class. The class decides the 2027 conformity route, not whether Article 14 applies today.

    What counts as evidence: A recorded classification verdict per product, with the rules version it was issued under.

    Article 7(1)answered by you

  6. 6. Components are monitored against vulnerability sources

    The 24-hour clock starts when the manufacturer becomes aware of an actively exploited vulnerability. Without monitoring, awareness arrives from a customer or an attacker.

    What counts as evidence: A recurring check of the component inventory against NVD/OSV and CISA KEV, with an owner.

    Article 14(1) and Article 3(42)answered by you

  7. 7. A named person owns the 24-hour early warning

    The first deadline is 24 hours from awareness, including weekends. An unassigned duty is missed by default.

    What counts as evidence: A named owner and deputy, with the escalation path written down.

    Article 14(2)(a)answered by you

  8. 8. The CSIRT designated as coordinator is identified

    Reports go to the CSIRT of the Member State of your main establishment, and to ENISA, simultaneously. Which CSIRT that is should not be researched during the first hour of an incident.

    What counts as evidence: The CSIRT for your main establishment recorded, with its contact route.

    Article 14(7)answered by you

  9. 9. The route into the ENISA Single Reporting Platform is arranged

    Reporting runs through the SRP, which opens on 11 September 2026. ENISA asks manufacturers to register in the platform when filing a specific notification rather than in advance, and validation by the coordinating CSIRT happens after first access - it is not a precondition for meeting the 24-hour deadline. The part that can be done in advance is an EU Login account for the people who would file.

    What counts as evidence: An EU Login account for the primary and the backup reporter, plus the registration route read once against ENISA’s current guidance.

    Assigned Representative registration and notification guidance (updated 2026-08-03; interface functions 2026-08-14)answered by you

  10. 10. A coordinated vulnerability disclosure policy is published

    Annex I Part II(5) requires a CVD policy. It is also how a reporter reaches you before an exploit does.

    What counts as evidence: A published policy stating where to report, what to expect and in what timeframe.

    Annex I, Part II, point 5answered by you

  11. 11. A contact address for vulnerability reports is discoverable

    Annex I Part II(6) requires a contact address for reporting vulnerabilities; a security.txt file is the convention that makes it findable without a support ticket.

    What counts as evidence: A security.txt served over HTTPS, or an equivalent documented address.

    Annex I, Part II, point 6answered by you

  12. 12. There is a way to notify affected users

    Article 14(8) requires informing affected users about the vulnerability or incident and any corrective measures - where necessary in a structured, machine-readable format. This obligation cannot be discharged by any tool.

    What counts as evidence: A user-notification channel and a template, plus a machine-readable advisory format where applicable.

    Article 14(8)answered by you

  13. 13. The 2027 conformity route is known

    The class decides whether self-assessment is available or a notified body is required from 11 December 2027. Booking a notified body is not a same-quarter activity.

    What counts as evidence: The applicable Article 32 route recorded per product.

    Article 32answered by you

This checklist is versioned content, compiled 2026-08-26. It covers the reporting duty that applies now, not the full conformity programme that applies from 11 December 2027.