← Back to CRA Guide Last updated: September 5, 2026

CRA Compliance Checklist: Engineering Team Roadmap

A practical, actionable checklist for engineering teams preparing for the Cyber Resilience Act. Track your progress from assessment to compliance readiness.

Using This Checklist

This checklist breaks down CRA compliance into practical engineering tasks. It's organized by phase and priority. Use it to track your team's progress and identify gaps.

Roadmap Approach

We recommend a phased approach: start with assessment and foundational work, then move to security implementation, documentation, and finally validation. This checklist follows that structure.

Phase 1: Assessment & Planning

Before you start implementing, understand your starting point.

1.1

Determine CRA Applicability

Confirm your product is in scope (hardware or software with digital elements sold in EU).

⏱️ 1 hour Legal + Product
1.2

Classify Your Product

Determine if your product is Default, Important Class I, Class II, or Critical.

Take Assessment →
⏱️ 30 min Product Manager
1.3

Identify Conformity Assessment Path

Based on classification, determine if self-assessment is allowed or third-party is needed.

⏱️ 1 hour Compliance Lead
1.4

Inventory All Products

Create a list of all products/variants that need to comply with CRA.

⏱️ 2-4 hours Product + Engineering
1.5

Gap Assessment

Compare current security practices against all 22 CRA requirements.

Use Requirements Explorer →
⏱️ 4-8 hours Security + Engineering
1.6

Create Compliance Roadmap

Based on gaps, create a prioritized plan with milestones for the December 2027 deadline.

⏱️ 4-8 hours Engineering Lead

Phase 2: Security Foundations

Implement the core security capabilities required by CRA.

2.1

Implement Secure Development Lifecycle (SDL)

Establish security requirements, threat modeling, code review, and testing practices.

⏱️ 2-4 weeks Security + Engineering
2.2

Set Up SBOM Generation

Integrate SBOM generation into your build pipeline (CycloneDX or SPDX format).

SBOM Guide →
⏱️ 1-2 days DevOps + Engineering
2.3

Implement Secure Update Mechanism

Build capability to deliver signed, verified security updates to users.

⏱️ 1-4 weeks Engineering
2.4

Review & Fix Default Configurations

Ensure product ships secure by default: no default passwords, encryption enabled, minimal permissions.

⏱️ 1-2 weeks Engineering
2.5

Encrypt Data in Transit and at Rest

Implement TLS for all network communications, encrypt sensitive stored data.

⏱️ 1-3 weeks Engineering
2.6

Implement Logging & Anomaly Detection

Add security event logging and ability to detect/report potential security anomalies.

⏱️ 1-2 weeks Engineering

Phase 3: Vulnerability Management

Set up processes for handling security vulnerabilities.

3.1

Create Vulnerability Disclosure Policy (VDP)

Publish a policy explaining how researchers can report vulnerabilities.

VDP Builder →
⏱️ 2-4 hours Security + Legal
3.2

Set Up security.txt

Create and publish a security.txt file pointing to your VDP and security contact.

security.txt Generator →
⏱️ 30 min DevOps
3.3

Establish Vulnerability Tracking

Set up a system to track reported vulnerabilities from intake through resolution.

⏱️ 1-2 days Security
3.4

Create Incident Response Plan

Document procedures for responding to security incidents, including ENISA reporting.

Learn More →
⏱️ 4-8 hours Security + Management
3.5

Implement Dependency Scanning

Set up automated scanning for vulnerabilities in third-party dependencies.

⏱️ 1-2 days DevOps + Security

Phase 4: Documentation

Create the documentation required for conformity assessment.

4.1

Technical Documentation

Document product design, security architecture, and how requirements are met.

⏱️ 2-4 weeks Engineering + Technical Writer
4.2

Risk Assessment Documentation

Document cybersecurity risks, mitigations, and residual risk acceptance.

⏱️ 1-2 weeks Security
4.3

User Instructions

Create clear instructions for secure installation, configuration, and use of the product.

⏱️ 1 week Technical Writer
4.4

EU Declaration of Conformity

Prepare the formal declaration stating compliance with CRA requirements.

Declaration Template →
⏱️ 2-4 hours Compliance Lead
4.5

Support Period Declaration

Define and document the security support period (minimum 5 years or product lifetime).

⏱️ 1-2 hours Product + Legal

Phase 5: Validation & Certification

Verify compliance and complete the conformity assessment process.

5.1

Internal Compliance Review

Review all requirements against implementation evidence before external assessment.

Use Requirements Explorer →
⏱️ 1-2 weeks Security + Compliance
5.2

Security Testing

Conduct penetration testing, vulnerability assessment, and security code review.

⏱️ 2-4 weeks Security / External
5.3

Notified Body Assessment (if required)

For Class II/Critical products, engage a Notified Body for third-party assessment.

⏱️ 4-12 weeks Compliance Lead
5.4

Apply CE Marking

After successful conformity assessment, apply the CE marking to the product.

⏱️ 1-2 hours Product
5.5

Establish Ongoing Monitoring

Set up processes for continuous compliance monitoring and annual reviews.

⏱️ Ongoing Security + Compliance

Download & Track Your Progress

Use our digital tools to track your compliance progress:

CRA Compliance Dashboard showing readiness progress, requirement completion, and quick action links

Compliance Dashboard

Track your progress across all phases with visual metrics and quick action links.

Open Dashboard →

Start Your Compliance Journey

Take our free assessment to get a personalized roadmap based on your product and current state.

Start Free Assessment