Free resource
CRA engineering checklist for connected devices
Six areas every hardware team should review before the Cyber Resilience Act obligations hit their product line. Read the summary below, then download the full PDF with the detailed checks.
Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents. Most other obligations, including SBOM and security-by-design requirements, apply from 11 December 2027. This checklist turns those obligations into engineering tasks.
1. Vulnerability intake
A public, monitored way for anyone to report a vulnerability in your product.
- Published contact point
- Coordinated vulnerability disclosure policy
- Triage criteria
2. The 24/72-hour reporting procedure
Actively exploited vulnerabilities and severe incidents go to ENISA and the national CSIRT via the Single Reporting Platform.
- Early warning within 24 hours
- Detailed notification within 72 hours
- Final report
- Rehearsal
3. SBOM
A machine-readable list of every component in each firmware release.
- Generated in the build
- Covers third-party and vendor code
- Linked to monitoring
4. Security update plan
Users must receive security updates for the support period — at least 5 years, or the expected time of use if shorter.
- Defined support period
- Secure OTA or field update path
- Separation of security fixes
5. Secure boot and key management
The device only runs firmware you signed, and keys are protected.
- Chain of trust
- Key storage
- Debug interfaces
6. Logging and evidence
Enough information to detect incidents and document decisions.
- Security-relevant events
- Technical documentation
- Decision log
We provide engineering solutions that prepare your device for the requirements of the Cyber Resilience Act. We do not provide legal advice and we are not a conformity assessment (CE) body.
Discuss your project
Describe your device and goal. An engineer replies within one business day.
Prefer e-mail?
[email protected]- Reply within one business day
- NDA available before any technical deep-dive
Our offices
Opole (Headquarters): ul. Technologiczna 2, 45-837 Opole
Wrocław (Office): ul. Strzegomska 42B, 53-611 Wrocław
Warsaw (Office): ul. Żurawia 6/12, 00-503 Warsaw