This Cyber Resilience Act compliance checklist turns Regulation (EU) 2024/2847 into 24 concrete checks you can run against a single product. It is a free Excel file built for product security leads, CISOs and compliance managers who need to show that their products with digital elements meet the CRA before its obligations bite. Instead of re-reading the whole regulation, you work down a list that maps to the Annex I essential requirements, the software bill of materials duty, the coordinated vulnerability-handling process and the reporting timelines to ENISA. Each row tells you what good looks like and where the evidence lives. Download it below, share it with engineering and use it as the backbone of your CRA readiness review.
Get the EU Cyber Resilience Act Checklist
Check your product against the CRA essential requirements, SBOM and vulnerability-reporting duties. 24 items.

What the Cyber Resilience Act compliance checklist covers
The file is a single worksheet of 24 items grouped into the areas the CRA actually cares about. Every row carries the same columns: the requirement in plain language, what good looks like, the evidence that proves it, an owner and a status field you can set to Met, Partial or Gap. That structure means the checklist doubles as a live worklist, not just a reading exercise.
The 24 items fall into five blocks:
- Essential cybersecurity requirements. The Annex I product properties, from secure-by-default configuration to protecting the confidentiality and integrity of the data the product handles.
- Software bill of materials. Producing and maintaining a machine-readable SBOM so you and your customers know which components are inside the product.
- Vulnerability handling. A coordinated process to identify, document and remediate vulnerabilities across the support period.
- Security updates. Delivering updates for the defined support period so known vulnerabilities are actually fixed for users.
- Reporting. Notifying ENISA of actively exploited vulnerabilities and severe incidents within the required timelines.

EU Cyber Resilience Act the honest way: what actually matters
The CRA (Regulation (EU) 2024/2847) is not another management-system standard. It sets cybersecurity requirements for products with digital elements placed on the EU market, and its obligations attach to the product itself, not to your company's paperwork. That distinction is the one teams get wrong most often: CRA controls are product properties, not organisational processes, so they should not be conflated with an ISMS. A certified ISO 27001 estate does not, on its own, make a connected device compliant.
Five obligations carry the weight:
- Essential requirements. Every product must meet the Annex I essential cybersecurity requirements, the baseline security properties the product ships with.
- Security updates. Manufacturers must provide security updates across a defined support period so vulnerabilities keep getting fixed for as long as the product is in use.
- SBOM. You must produce and maintain a software bill of materials so the components inside the product are known and trackable.
- Vulnerability handling. A coordinated vulnerability-handling process has to identify, document and remediate issues across that same support period.
- Reporting. Actively exploited vulnerabilities and severe incidents must be reported to ENISA.
The calendar is the part most plans underestimate. The reporting obligations start on 11 September 2026, and the main manufacturer obligations apply from 11 December 2027. Work backwards from those two dates rather than treating the CRA as a distant problem. If you are weighing up tooling to carry this over time, our roundup of CRA compliance software walks through the options; everything else on this page assumes you are doing the readiness work yourself first.

How to use the Cyber Resilience Act compliance checklist
- Pick one product. The CRA works product by product, so scope the checklist to a single product with digital elements before you start.
- Assign owners. Give each of the 24 rows a named owner in engineering, security or product. Nothing moves without a person attached.
- Rate each item. Mark every row Met, Partial or Gap, and link the evidence next to it: a configuration baseline, the SBOM file, the vulnerability-handling policy, the update schedule.
- Fix the gaps against the dates. Sequence remediation so vulnerability and incident reporting is ready before 11 September 2026 and the full manufacturer obligations before 11 December 2027.
- Re-run before each release. Treat the checklist as a release gate, not a one-time exercise, and re-check it whenever the product changes materially.

Do this automatically in Venvera
The Excel file is a strong starting point, but a spreadsheet goes stale the moment the product changes. In Venvera, the same 24 checks live on the CRA framework as tracked controls with owners, due dates and evidence attached to each one. When your SBOM or vulnerability-handling policy is updated, the control status reflects it instead of quietly drifting out of date in a file nobody reopens. Because CRA product properties sit alongside your other obligations, evidence you already collected can be reused where it genuinely applies rather than gathered twice. Venvera starts from EUR 399/month. The manual checklist below gets you oriented today; the platform keeps the work current after that.
Frequently Asked Questions
When does the EU Cyber Resilience Act take effect?
The CRA phases in on two key dates. The reporting obligations start on 11 September 2026, and the main manufacturer obligations apply from 11 December 2027. Plan your vulnerability and incident reporting readiness against the earlier date, because that is when notifications to ENISA become due.
Does the CRA replace ISO 27001 or my ISMS?
No. CRA controls are product properties, not organisational processes, so they should not be conflated with an ISMS. An ISO 27001 certificate describes how your organisation manages security; the CRA asks whether a specific product meets the Annex I essential requirements, ships an SBOM and has a working vulnerability-handling process.
What is an SBOM and why does the CRA require one?
A software bill of materials is a machine-readable inventory of the components inside your product. The CRA requires manufacturers to produce and maintain one so vulnerabilities in third-party components can be found and fixed across the support period, rather than staying invisible until they are exploited.
Who has to comply with the Cyber Resilience Act?
Manufacturers placing products with digital elements on the EU market. They must meet the Annex I essential requirements, provide security updates for a support period, produce and maintain an SBOM, run a coordinated vulnerability-handling process and report actively exploited vulnerabilities and severe incidents to ENISA.




