CRA compliance checklist
CRA compliance happens in two phases: reporting readiness now, because Art. 14 applies since 11 September 2026, and full conformity with the essential requirements by 11 December 2027. This checklist orders the steps software manufacturers should take.
Last updated:
Phase 1: now (reporting readiness)
- List all products with digital elements you place on the EU market, including older versions still in use.
- Determine your role for each (manufacturer, importer, distributor) and check scope, including SaaS components.
- Assign a responsible owner and deputies for CRA reporting.
- Register with the ENISA Single Reporting Platform and identify your competent CSIRT.
- Create an SBOM for each product and keep it current.
- Set up vulnerability monitoring for your code and dependencies.
- Publish a contact address for vulnerability reports and a coordinated vulnerability disclosure policy.
- Write and test a reporting runbook for the 24h / 72h / final report stages.
Phase 2: by 11 December 2027 (full conformity)
- Classify each product: default, important (Class I/II) or critical.
- Carry out and document a cybersecurity risk assessment per product.
- Implement the Annex I Part I requirements (secure defaults, access control, data protection, attack surface, logging, updates).
- Formalise vulnerability handling per Annex I Part II, including regular testing.
- Define and publish the support period (at least five years unless expected use is shorter).
- Compile technical documentation (Annex VII) and user information (Annex II).
- Perform the conformity assessment (Module A for standard products).
- Draw up the EU declaration of conformity and affix the CE marking.
- Keep documentation for ten years or the support period, whichever is longer.
For background, see the CRA overview.