Cyber Resilience Act (CRA) checklist.
What a connected product (IoT sensor, gateway, embedded Linux board, microcontroller firmware) must have in place for Regulation (EU) 2024/2847: classification, security by design, SBOM, vulnerability handling, 24-hour reporting and the file behind CE marking. Printable, usable in project reviews.
Written by our design house from the text of the regulation. Watch out: the reporting obligation has applied since 11 September 2026, including to products already sold, well before the general 11 December 2027 deadline.
-
Scope and classification: product with digital elements or not, default, important (class I and II) or critical category, products already on the market, overlap with RED.
-
Security by design: risk assessment, secure by default, secure boot, signed OTA updates with anti-rollback, reduced attack surface.
-
SBOM and components: CycloneDX or SPDX software inventory generated on every build, continuous CVE monitoring of dependencies.
-
Vulnerability handling: coordinated disclosure policy, point of contact, free security updates, five-year minimum support period.
-
Reporting (in force since 11 September 2026): 24 h early warning, 72 h notification, final report, ENISA single reporting platform.
-
Documentation and CE marking: technical documentation, EU declaration of conformity, user information, 11 December 2027 deadline.