Skip to content
BCF Embedded by Bright Coders' Factory (home page)
Discuss your project

Free resource

CRA engineering checklist for connected devices

Six areas every hardware team should review before the Cyber Resilience Act obligations hit their product line. Read the summary below, then download the full PDF with the detailed checks.

Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents. Most other obligations, including SBOM and security-by-design requirements, apply from 11 December 2027. This checklist turns those obligations into engineering tasks.

1. Vulnerability intake

A public, monitored way for anyone to report a vulnerability in your product.

  • Published contact point
  • Coordinated vulnerability disclosure policy
  • Triage criteria

2. The 24/72-hour reporting procedure

Actively exploited vulnerabilities and severe incidents go to ENISA and the national CSIRT via the Single Reporting Platform.

  • Early warning within 24 hours
  • Detailed notification within 72 hours
  • Final report
  • Rehearsal

3. SBOM

A machine-readable list of every component in each firmware release.

  • Generated in the build
  • Covers third-party and vendor code
  • Linked to monitoring

4. Security update plan

Users must receive security updates for the support period — at least 5 years, or the expected time of use if shorter.

  • Defined support period
  • Secure OTA or field update path
  • Separation of security fixes

5. Secure boot and key management

The device only runs firmware you signed, and keys are protected.

  • Chain of trust
  • Key storage
  • Debug interfaces

6. Logging and evidence

Enough information to detect incidents and document decisions.

  • Security-relevant events
  • Technical documentation
  • Decision log

We provide engineering solutions that prepare your device for the requirements of the Cyber Resilience Act. We do not provide legal advice and we are not a conformity assessment (CE) body.

Sources

Discuss your project

Describe your device and goal. An engineer replies within one business day.

Prefer e-mail?

[email protected]
  • Reply within one business day
  • NDA available before any technical deep-dive

Our offices

Opole (Headquarters): ul. Technologiczna 2, 45-837 Opole

Wrocław (Office): ul. Strzegomska 42B, 53-611 Wrocław

Warsaw (Office): ul. Żurawia 6/12, 00-503 Warsaw

BCF Embedded by Bright Coders' Factory (home page)

Firmware, hardware and security engineering for connected devices — from PoC to production.


BCF Software Sp. z o.o.

ul. Technologiczna 2, 45-837 Opole, Poland

NIP: PL 754 31 26 298 · KRS: 0000634606 · REGON: 365280382

[email protected]

Offices

Opole (Headquarters) — ul. Technologiczna 2, 45-837 Opole

Wrocław (Office) — ul. Strzegomska 42B, 53-611 Wrocław

Warsaw (Office) — ul. Żurawia 6/12, 00-503 Warsaw

© 2026 BCF Embedded by Bright Coders' Factory. All rights reserved.

Privacy & cookie policy