Your Practical Compliance Checklist
Ensure you hit every milestone before the December 2027 deadline.
Phase 1: Assessment
- Determine Product Classification (Default, Class I, Class II)
- Conduct a cybersecurity risk assessment
- Identify all third-party and open-source dependencies
Phase 2: Technical Implementation
- Generate an automated SBOM (CycloneDX/SPDX)
- Ensure product is "Secure by Default" (no default passwords, closed ports)
- Implement a secure update mechanism
- Encrypt sensitive data at rest and in transit
Phase 3: Processes & Reporting
- Establish a Vulnerability Disclosure Policy (VDP)
- Publish a security.txt file
- Set up 24/7 ENISA reporting pipelines for Article 14
Generate your security.txt for free today to cross the first item off your list!
Get the CRA deadline calendar
A one-page PDF showing every CRA date that matters for your product team. Free — no spam, unsubscribe anytime.
Related articles
Ready to Take Action?
Start your CRA compliance journey with our free assessment tool.