Skip to content
BCF Embedded by Bright Coders' Factory (home page)
Discuss your project

Free resource

CRA engineering checklist for connected devices

Six areas every hardware team should review before the Cyber Resilience Act obligations hit their product line. Read the summary below, then download the full PDF with the detailed checks.

Since 11 September 2026 manufacturers must report actively exploited vulnerabilities and severe incidents. Most other obligations, including SBOM and security-by-design requirements, apply from 11 December 2027. This checklist turns those obligations into engineering tasks.

1. Vulnerability intake

A public, monitored way for anyone to report a vulnerability in your product.

  • Published contact point
  • Coordinated vulnerability disclosure policy
  • Triage criteria

2. The 24/72-hour reporting procedure

Actively exploited vulnerabilities and severe incidents go to ENISA and the national CSIRT via the Single Reporting Platform.

  • Early warning within 24 hours
  • Detailed notification within 72 hours
  • Final report
  • Rehearsal

3. SBOM

A machine-readable list of every component in each firmware release.

  • Generated in the build
  • Covers third-party and vendor code
  • Linked to monitoring

4. Security update plan

Users must receive security updates for the support period - at least 5 years, or the expected time of use if shorter.

  • Defined support period
  • Secure OTA or field update path
  • Separation of security fixes

5. Secure boot and key management

The device only runs firmware you signed, and keys are protected.

  • Chain of trust
  • Key storage
  • Debug interfaces

6. Logging and evidence

Enough information to detect incidents and document decisions.

  • Security-relevant events
  • Technical documentation
  • Decision log

We provide engineering solutions that prepare your device for the requirements of the Cyber Resilience Act. We do not provide legal advice and we are not a conformity assessment (CE) body.

Sources

Discuss your project

Describe your device and goal. An engineer replies within one business day.

Prefer e-mail?

[email protected]
  • We reply within one business day
  • NDA before technical discussions
BCF Embedded by Bright Coders' Factory (home page)

Firmware, hardware and security engineering for connected devices - from PoC to production.

Contact

[email protected]

Company

BCF Software Sp. z o.o.

TAX ID (NIP): PL 754 31 26 298

KRS: 0000634606

REGON: 365280382

NCAGE Code: 9CT2H

Dun & Bradstreet D-U-N-S©: 366333788

Our Addresses

Opole (Headquarters)

ul. Technologiczna 2, 45-837 Opole

Wrocław (Office)

ul. Strzegomska 42B, 53-611 Wrocław

Warsaw (Office)

ul. Żurawia 6/12, 00-503 Warsaw

Schwäbisch Hall (Office, Germany)

Technologiezentrum, Stauffenbergstraße 35-38, 74523 Schwäbisch Hall, Germany

London (Office, United Kingdom)

71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom

© 2026 Bcf-software.com All rights reserved

Privacy & cookie policy