Checklist

Cyber Resilience Act Compliance Checklist

The ultimate compliance checklist for software developers and hardware manufacturers. Track your progress toward full CRA compliance.

March 2026 · 5 min read

Your Practical Compliance Checklist

Ensure you hit every milestone before the December 2027 deadline.

Phase 1: Assessment

  • Determine Product Classification (Default, Class I, Class II)
  • Conduct a cybersecurity risk assessment
  • Identify all third-party and open-source dependencies

Phase 2: Technical Implementation

  • Generate an automated SBOM (CycloneDX/SPDX)
  • Ensure product is "Secure by Default" (no default passwords, closed ports)
  • Implement a secure update mechanism
  • Encrypt sensitive data at rest and in transit

Phase 3: Processes & Reporting

  • Establish a Vulnerability Disclosure Policy (VDP)
  • Publish a security.txt file
  • Set up 24/7 ENISA reporting pipelines for Article 14

Generate your security.txt for free today to cross the first item off your list!

Get the CRA deadline calendar

A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.

Related articles

Ready to Take Action?

Start your CRA compliance journey with our free assessment tool.

Need help with CRA? Ask the assistant.
Need help with CRA? Ask the assistant.