Skip to main content
← All posts·
Regulatory Compliance

CRA Compliance Checklist: 45-Point Guide for Software Manufacturers [2026]

Complete Cyber Resilience Act compliance checklist for software manufacturers and IoT vendors. 45 action items covering essential requirements, vulnerability handling, SBOM, conformity assessment, and the September 2026 reporting deadline.

Luca Berton13 min read

How to Use This Checklist

The Cyber Resilience Act applies to manufacturers of products with digital elements — from IoT devices to enterprise software. The first deadline is 11 September 2026 for vulnerability reporting obligations. Full compliance is required by 11 December 2027. Score each item: 0 (Not started), 1 (In progress), 2 (Implemented).

Phase 1: Product Classification (5 items)

Determine Your Obligations

  1. Product inventory completed — all products with digital elements catalogued
  2. Each product classified: default, Important Class I, Important Class II, or Critical
  3. Conformity assessment path identified per product category (self-assessment for default, third-party for Important/Critical)
  4. Support period defined for each product (minimum 5 years or expected product lifetime)
  5. Exemptions assessed — do any products fall under MDR, aviation, or automotive sector-specific regulations?

Phase 1 Score: ___ / 10

Phase 2: Secure Development (8 items)

  1. Secure development lifecycle (SDLC) documented and followed
  2. Threat modelling performed for each product
  3. Static analysis (SAST) integrated into CI/CD pipeline
  4. Dynamic analysis (DAST) performed regularly
  5. Dependency scanning for known vulnerabilities (all third-party components)
  6. Security testing performed before each release (including regression tests for previous vulnerabilities)
  7. Code review process includes security review for critical components
  8. Build environment secured — reproducible builds, access-controlled CI/CD

Phase 2 Score: ___ / 16

📘 Book

Kubernetes Recipes

Practical guide for container orchestration and deployment — hands-on patterns you can use today.

View on Amazon →

Phase 3: Essential Cybersecurity Requirements (8 items)

  1. Products delivered with secure-by-default configuration (no known exploitable vulnerabilities)
  2. Authentication mechanisms protect against unauthorised access
  3. Data at rest and in transit is encrypted using state-of-the-art cryptography
  4. Attack surface minimised — only necessary ports, protocols, and services enabled
  5. Confidentiality, integrity, and availability of data protected
  6. Products designed to limit exploitation impact (least privilege, segmentation)
  7. Logging of security-relevant events enabled
  8. Security updates can be delivered reliably, automatically where appropriate

Phase 3 Score: ___ / 16

Phase 4: Vulnerability Handling (7 items) — September 2026 Deadline

⚠️ These requirements apply from 11 September 2026

  1. Coordinated vulnerability disclosure (CVD) process established and publicly documented
  2. Contact point for vulnerability reports accessible and responsive
  3. Actively exploited vulnerabilities reported to ENISA within 24 hours of awareness
  4. Severe vulnerabilities (not yet exploited) reported within 72 hours
  5. Vulnerability remediation process with defined SLAs (critical: days, high: weeks)
  6. Security advisory publication process — users notified of vulnerabilities and patches
  7. Component inventory maintained for vulnerability correlation (which products use which components)

Phase 4 Score: ___ / 14

🎓 Course

Automating Azure DevTest Labs

Automate lab management and integrate with CI/CD pipelines.

Start on Pluralsight →

Phase 5: SBOM & Documentation (7 items)

  1. SBOM generated for each product release (CycloneDX or SPDX format)
  2. SBOM includes at minimum all top-level dependencies
  3. SBOM delivery mechanism defined (machine-readable, available to customers and authorities)
  4. Technical documentation prepared per Annex VII (design, development, assessment, vulnerability handling)
  5. User information provided — secure configuration instructions, support contact, update procedures
  6. Open-source component licence compliance verified
  7. Third-party component risk assessment documented

Phase 5 Score: ___ / 14

Phase 6: Conformity & Market Placement (10 items)

  1. Conformity assessment completed (self for default, third-party for Important/Critical)
  2. EU declaration of conformity drawn up
  3. CE marking affixed to product or packaging
  4. Technical documentation retained for 10 years after product placed on market
  5. Market surveillance authority notification process established
  6. Post-market monitoring system operational — tracking vulnerability reports, user feedback, and component updates
  7. Recall/withdrawal procedure documented for products with non-compliant vulnerabilities
  8. Supply chain notification — inform distributors and importers of known vulnerabilities
  9. Designated EU representative appointed (if manufacturer is outside the EU)
  10. Internal compliance review schedule established (annual minimum)

Phase 6 Score: ___ / 20

🚀 Need Help?

AI Platform Assessment

Get a 2-3 week infrastructure audit with a concrete roadmap. No big-consultancy overhead.

Book Your Free Assessment →

Scoring Guide

  • 75-90: Strong compliance posture. Proceed to formal conformity assessment.
  • 55-74: Good foundation. Focus on Phase 4 (vulnerability handling) — September 2026 deadline is imminent.
  • 35-54: Significant gaps. Prioritise Phases 2-4 (secure development and vulnerability handling).
  • 15-34: Early stage. Start with Phase 1 (classification) and Phase 4 (vulnerability handling for September 2026).
  • 0-14: Pre-compliance. Immediate mobilisation required. Engage legal and engineering leadership.
CRA
compliance checklist
software manufacturers
SBOM
vulnerability handling
CE marking

Related Solution

Navigating AI adoption in a regulated environment? Our readiness assessment maps infrastructure, governance, and compliance gaps in 2-3 weeks.

Explore AI Readiness for Regulated Enterprises →

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →