Guide

CRA Compliance Step-by-Step: The Complete 2026 Roadmap

A practical 8-step roadmap to achieve EU Cyber Resilience Act compliance. From initial assessment to CE marking — with free tools at every step.

March 2026 · 12 min read

Why Start CRA Compliance Now?

The EU Cyber Resilience Act (Regulation 2024/2847) takes full effect on December 11, 2027. But Article 14 reporting obligations begin September 11, 2026. Starting now gives you the runway to fix security debt, integrate tooling, and document your processes.

Key Takeaway

CRA compliance is an 8-step process. Most software companies can self-certify using free tools. Start with the assessment, not the paperwork.

Step 1: Assess CRA Applicability

Take the free 5-minute assessment to determine your product classification (Default, Class I, or Class II) and which of the 22 requirements are relevant.

Step 2: Generate Your SBOM

CRA Annex I Part II, §1 mandates a Software Bill of Materials. Use CycloneDX CLI, Syft, or Trivy and integrate into your CI/CD pipeline. See our SBOM Requirements Guide.

Step 3: Run a Dependency Vulnerability Scan

Use OWASP Dependency-Track, Trivy, or Dependabot to identify known vulnerabilities in dependencies.

Step 4: Publish Security Contact Information

Create security@yourcompany.com, publish /.well-known/security.txt using our free generator, and write a Vulnerability Disclosure Policy.

Step 5: Conduct Product Risk Assessment

CRA Article 13(2) requires a documented cybersecurity risk assessment. Use our Risk Assessment Wizard (aligned with BSI TR-03183-1).

Step 6: Fix Critical Vulnerabilities

Address by severity: Critical (CVSS 9.0+) immediately, High (7.0-8.9) within 30 days, Medium (4.0-6.9) within 90 days.

Step 7: Prepare Technical Documentation

Compile product description, risk assessment, SBOM, test reports, vulnerability handling procedures, and post-market monitoring plan. Keep for 10 years.

Step 8: Issue Declaration of Conformity & CE Mark

For Default category: self-Declaration of Conformity and CE mark. For Class I/II: engage a notified body.

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.