How to Use This Checklist
The Cyber Resilience Act applies to manufacturers of products with digital elements — from IoT devices to enterprise software. The first deadline is 11 September 2026 for vulnerability reporting obligations. Full compliance is required by 11 December 2027. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented).
Phase 1: Product Classification (5 items)
Determine Your Obligations
- Product inventory completed — all products with digital elements catalogued
- Each product classified: default, Important Class I, Important Class II, or Critical
- Conformity assessment path identified per product category (self-assessment for default, third-party for Important/Critical)
- Support period defined for each product (minimum 5 years or expected product lifetime)
- Exemptions assessed — do any products fall under MDR, aviation, or automotive sector-specific regulations?
Phase 1 Score: ___ / 10
Phase 2: Secure Development (8 items)
- Secure development lifecycle (SDLC) documented and followed
- Threat modelling performed for each product
- Static analysis (SAST) integrated into CI/CD pipeline
- Dynamic analysis (DAST) performed regularly
- Dependency scanning for known vulnerabilities (all third-party components)
- Security testing performed before each release (including regression tests for previous vulnerabilities)
- Code review process includes security review for critical components
- Build environment secured — reproducible builds, access-controlled CI/CD
Phase 2 Score: ___ / 16
Kubernetes Recipes
Practical guide for container orchestration and deployment — hands-on patterns you can use today.
View on Amazon →Phase 3: Essential Cybersecurity Requirements (8 items)
- Products delivered with secure-by-default configuration (no known exploitable vulnerabilities)
- Authentication mechanisms protect against unauthorised access
- Data at rest and in transit is encrypted using state-of-the-art cryptography
- Attack surface minimised — only necessary ports, protocols, and services enabled
- Confidentiality, integrity, and availability of data protected
- Products designed to limit exploitation impact (least privilege, segmentation)
- Logging of security-relevant events enabled
- Security updates can be delivered reliably, automatically where appropriate
Phase 3 Score: ___ / 16
Phase 4: Vulnerability Handling (7 items) — September 2026 Deadline
⚠️ These requirements apply from 11 September 2026
- Coordinated vulnerability disclosure (CVD) process established and publicly documented
- Contact point for vulnerability reports accessible and responsive
- Actively exploited vulnerabilities reported to ENISA within 24 hours of awareness
- Severe vulnerabilities (not yet exploited) reported within 72 hours
- Vulnerability remediation process with defined SLAs (critical: days, high: weeks)
- Security advisory publication process — users notified of vulnerabilities and patches
- Component inventory maintained for vulnerability correlation (which products use which components)
Phase 4 Score: ___ / 14
Automating Azure DevTest Labs
Automate lab management and integrate with CI/CD pipelines.
Start on Pluralsight →Phase 5: SBOM & Documentation (7 items)
- SBOM generated for each product release (CycloneDX or SPDX format)
- SBOM includes at minimum all top-level dependencies
- SBOM delivery mechanism defined (machine-readable, available to customers and authorities)
- Technical documentation prepared per Annex VII (design, development, assessment, vulnerability handling)
- User information provided — secure configuration instructions, support contact, update procedures
- Open-source component licence compliance verified
- Third-party component risk assessment documented
Phase 5 Score: ___ / 14
Phase 6: Conformity & Market Placement (10 items)
- Conformity assessment completed (self for default, third-party for Important/Critical)
- EU declaration of conformity drawn up
- CE marking affixed to product or packaging
- Technical documentation retained for 10 years after product placed on market
- Market surveillance authority notification process established
- Post-market monitoring system operational — tracking vulnerability reports, user feedback, and component updates
- Recall/withdrawal procedure documented for products with non-compliant vulnerabilities
- Supply chain notification — inform distributors and importers of known vulnerabilities
- Designated EU representative appointed (if manufacturer is outside the EU)
- Internal compliance review schedule established (annual minimum)
Phase 6 Score: ___ / 20
AI Platform Assessment
Get a 2-3 week infrastructure audit with a concrete roadmap. No big-consultancy overhead.
Book Your Free Assessment →Scoring Guide
- 75-90: Strong compliance posture. Proceed to formal conformity assessment.
- 55-74: Good foundation. Focus on Phase 4 (vulnerability handling) — September 2026 deadline is imminent.
- 35-54: Significant gaps. Prioritise Phases 2-4 (secure development and vulnerability handling).
- 15-34: Early stage. Start with Phase 1 (classification) and Phase 4 (vulnerability handling for September 2026).
- 0-14: Pre-compliance. Immediate mobilisation required. Engage legal and engineering leadership.
Related Solution
Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.
Explore AI Readiness for Regulated Enterprises →
Luca Berton
