NEWVenvera speaks your language: the full platform, in English, German, Spanish and Bulgarian.See what’s new →
Cyber Resilience Act Compliance Checklist (Free Excel)
Resources

Cyber Resilience Act Compliance Checklist (Free Excel)

·Alexander Sverdlov

This Cyber Resilience Act compliance checklist turns Regulation (EU) 2024/2847 into 24 concrete checks you can run against a single product. It is a free Excel file built for product security leads, CISOs and compliance managers who need to show that their products with digital elements meet the CRA before its obligations bite. Instead of re-reading the whole regulation, you work down a list that maps to the Annex I essential requirements, the software bill of materials duty, the coordinated vulnerability-handling process and the reporting timelines to ENISA. Each row tells you what good looks like and where the evidence lives. Download it below, share it with engineering and use it as the backbone of your CRA readiness review.

Free download

Get the EU Cyber Resilience Act Checklist

Check your product against the CRA essential requirements, SBOM and vulnerability-reporting duties. 24 items.

By downloading, you agree to receive occasional relevant emails from Venvera. Unsubscribe anytime. See our Privacy Policy. This template is a starting point, not legal advice.

One evidence library covering the CRA and overlapping frameworks
One evidence library, mapped across the CRA and the frameworks it shares controls with.

What the Cyber Resilience Act compliance checklist covers

The file is a single worksheet of 24 items grouped into the areas the CRA actually cares about. Every row carries the same columns: the requirement in plain language, what good looks like, the evidence that proves it, an owner and a status field you can set to Met, Partial or Gap. That structure means the checklist doubles as a live worklist, not just a reading exercise.

The 24 items fall into five blocks:

  • Essential cybersecurity requirements. The Annex I product properties, from secure-by-default configuration to protecting the confidentiality and integrity of the data the product handles.
  • Software bill of materials. Producing and maintaining a machine-readable SBOM so you and your customers know which components are inside the product.
  • Vulnerability handling. A coordinated process to identify, document and remediate vulnerabilities across the support period.
  • Security updates. Delivering updates for the defined support period so known vulnerabilities are actually fixed for users.
  • Reporting. Notifying ENISA of actively exploited vulnerabilities and severe incidents within the required timelines.
Mapping a the CRA control across other frameworks
A control entered once maps across the CRA and every framework it also satisfies.

EU Cyber Resilience Act the honest way: what actually matters

The CRA (Regulation (EU) 2024/2847) is not another management-system standard. It sets cybersecurity requirements for products with digital elements placed on the EU market, and its obligations attach to the product itself, not to your company's paperwork. That distinction is the one teams get wrong most often: CRA controls are product properties, not organisational processes, so they should not be conflated with an ISMS. A certified ISO 27001 estate does not, on its own, make a connected device compliant.

Five obligations carry the weight:

  1. Essential requirements. Every product must meet the Annex I essential cybersecurity requirements, the baseline security properties the product ships with.
  2. Security updates. Manufacturers must provide security updates across a defined support period so vulnerabilities keep getting fixed for as long as the product is in use.
  3. SBOM. You must produce and maintain a software bill of materials so the components inside the product are known and trackable.
  4. Vulnerability handling. A coordinated vulnerability-handling process has to identify, document and remediate issues across that same support period.
  5. Reporting. Actively exploited vulnerabilities and severe incidents must be reported to ENISA.

The calendar is the part most plans underestimate. The reporting obligations start on 11 September 2026, and the main manufacturer obligations apply from 11 December 2027. Work backwards from those two dates rather than treating the CRA as a distant problem. If you are weighing up tooling to carry this over time, our roundup of CRA compliance software walks through the options; everything else on this page assumes you are doing the readiness work yourself first.

the CRA control health tracked in one dashboard
Track the CRA readiness continuously instead of in a point-in-time spreadsheet.

How to use the Cyber Resilience Act compliance checklist

  1. Pick one product. The CRA works product by product, so scope the checklist to a single product with digital elements before you start.
  2. Assign owners. Give each of the 24 rows a named owner in engineering, security or product. Nothing moves without a person attached.
  3. Rate each item. Mark every row Met, Partial or Gap, and link the evidence next to it: a configuration baseline, the SBOM file, the vulnerability-handling policy, the update schedule.
  4. Fix the gaps against the dates. Sequence remediation so vulnerability and incident reporting is ready before 11 September 2026 and the full manufacturer obligations before 11 December 2027.
  5. Re-run before each release. Treat the checklist as a release gate, not a one-time exercise, and re-check it whenever the product changes materially.
A live the CRA posture for the board
A live posture keeps the the CRA picture current for leadership and auditors.

Do this automatically in Venvera

The Excel file is a strong starting point, but a spreadsheet goes stale the moment the product changes. In Venvera, the same 24 checks live on the CRA framework as tracked controls with owners, due dates and evidence attached to each one. When your SBOM or vulnerability-handling policy is updated, the control status reflects it instead of quietly drifting out of date in a file nobody reopens. Because CRA product properties sit alongside your other obligations, evidence you already collected can be reused where it genuinely applies rather than gathered twice. Venvera starts from EUR 399/month. The manual checklist below gets you oriented today; the platform keeps the work current after that.

Frequently Asked Questions

When does the EU Cyber Resilience Act take effect?

The CRA phases in on two key dates. The reporting obligations start on 11 September 2026, and the main manufacturer obligations apply from 11 December 2027. Plan your vulnerability and incident reporting readiness against the earlier date, because that is when notifications to ENISA become due.

Does the CRA replace ISO 27001 or my ISMS?

No. CRA controls are product properties, not organisational processes, so they should not be conflated with an ISMS. An ISO 27001 certificate describes how your organisation manages security; the CRA asks whether a specific product meets the Annex I essential requirements, ships an SBOM and has a working vulnerability-handling process.

What is an SBOM and why does the CRA require one?

A software bill of materials is a machine-readable inventory of the components inside your product. The CRA requires manufacturers to produce and maintain one so vulnerabilities in third-party components can be found and fixed across the support period, rather than staying invisible until they are exploited.

Who has to comply with the Cyber Resilience Act?

Manufacturers placing products with digital elements on the EU market. They must meet the Annex I essential requirements, provide security updates for a support period, produce and maintain an SBOM, run a coordinated vulnerability-handling process and report actively exploited vulnerabilities and severe incidents to ENISA.

Alexander Sverdlov

Alexander Sverdlov

CEO & Founder

Alexander is the founder of Venvera and a 20+ year veteran of European cybersecurity and compliance. He has led security and risk programmes for regulated financial institutions, fintechs and SaaS companies operating under DORA, NIS2, GDPR, ISO 27001 and the EU AI Act. Before Venvera, he founded Atlant Security, an offensive security consultancy that ran penetration tests, red-team exercises and ISO 27001 readiness programmes for clients across the EU and the Middle East. He writes on the cross-framework realities of running modern compliance: how to map one control to many obligations, where the spreadsheets fall apart, and what regulators are actually asking for once the auditor sits down.

More articles by Alexander

RELATED POSTS