CRA Compliance Checklist | Sonatype Guide

CRA Compliance Checklist

Download the Checklist

The Cyber Resilience Act (CRA), covers all products with digital elements that can be connected to a device or a network. The CRA includes eight annexes that provide detailed requirements and standards, including Essential Cybersecurity Requirements (Annex I) and Reporting Obligations of Manufacturers (Article 11). Only products that comply with these requirements will be allowed on the market. Technical documentation proving compliance is necessary, and imported products require a CE mark.

This checklist covers key elements of Annex I and Article 11, and how Sonatype can help support compliance throughout the SDLC.

Questions to Consider Your Preparedness to Comply with CRA Requirements

Risk Assessment

Incident Response

Data Protection

Standards and Policies

Access Control and Third-Parties

Reporting Obligations

How Sonatype Can Help Optimise and Protect Your Software Supply Chain

Vulnerability scanning is central to the CRA, and only products that comply with the security and vulnerability management requirements above will be allowed on the market. Products will be presumed to be compliant, but sanctions will apply if they are discovered not to be. The Sonatype platform can help developers gather and report on compliance information, identify vulnerabilities, and meet the reporting requirements. To learn more about how we can help you ensure compliance, download our CRA User’s Guide to Compliance.

See How Sonatype SBOM Manager Can Help You Comply with the CRA

Book a Demo