Classify the product
Confirm whether the product is a product with digital elements, its intended use and the role of manufacturer, importer or distributor.
Cyber Resilience Act - Regulation (EU) 2024/2847
CRAReady helps manufacturers, SaaS publishers and importers selling in the EU frame CRA obligations: product scope, security by design, SBOM, vulnerability handling, EU declaration and incident notification.
Content based on official European Commission, EUR-Lex and ENISA pages. It is not legal advice.
Estimate readiness in 5 minutes. The weighted score highlights gaps that block a conformity file: economic role, evidence, SBOM, disclosure process, technical documentation and security support.
Confirm whether the product is a product with digital elements, its intended use and the role of manufacturer, importer or distributor.
Build an SBOM per version and connect dependencies, third-party components, licences, owners and support status.
Document intake, triage, remediation, coordinated disclosure, evidence and Article 14 notification readiness.
Prepare technical documentation, conformity assessment, EU declaration and security instructions for users.
A usable CRA programme connects every product version to its components, known vulnerabilities, triage decisions, fixes and notifications.
Generate CycloneDX/SPDX for application, image, firmware, dependencies and third-party components; keep hash, date and owner.
Monitor NVD, supplier advisories, GitHub Security Advisories, OSV and critical component bulletins.
Assess exploitability, EU exposure, severity, affected versions, workaround and remediation decision.
Define SLA by severity, test evidence, advisory publication and secure update channel.
Publish security.txt, contact, optional PGP key, intake policy and acknowledgement process.
Prepare 24h early warning, 72h notification, final report 14 days after a fix or one month for severe incident.
Short texts to start the file. Replace bracketed fields, validate with legal/compliance and keep history per product version.
EU declaration
Template for software, SaaS or connected hardware made available on the EU market.
We, [manufacturer], declare under our sole responsibility that [product/version] conforms with applicable requirements of Regulation (EU) 2024/2847. Intended use: [use]. Technical documentation: [reference]. Applied standards/specifications: [list]. Security contact: [email]. Signature: [name, role, date].
24h notification
First message when an actively exploited vulnerability or severe incident is known.
Product: [name/version]. Type: [exploited vulnerability/severe incident]. Awareness time: [UTC]. Known affected Member States: [list]. Suspected malicious act: [yes/no/unknown]. Immediate measures: [containment]. Crisis contact: [name/email/phone].
72h notification
Technical details, initial assessment and user mitigation measures.
Nature: [CVE/incident]. Affected versions: [list]. Initial impact: [confidentiality/integrity/availability]. Corrective or mitigating measures taken: [details]. User actions: [patch/configuration]. Information sensitivity: [level].
Final report
Close treatment with root cause, impact, fix and prevention.
Summary: [incident/vulnerability]. Root cause: [analysis]. Timeline: [UTC dates]. Severity and actual impact: [details]. Fix available: [version/link/hash]. User communication: [date/channel]. Preventive measures: [backlog and owners].
These milestones guide operational preparation. Official dates confirm progressive application before the general application date.
Crawlable guides for CRA preparation queries by role and deliverable.
Frame manufacturer role, security-by-design requirements, technical file, EU declaration and security support before 2027.
Operational plan to generate an SBOM, monitor CVEs, handle vulnerabilities and document decisions.
Prepare CRA notification fields for an exploited vulnerability or severe incident from September 2026.
Understand requested evidence, product documentation, market placement responsibilities and supplier controls.
Send your product type, target EU market, number of active versions and current SBOM maturity. Response with a short audit plan.