Skip to main content

    Cyber Resilience Act for Software and Connected Products

    Basenorm centralises CRA obligations including secure development, vulnerability handling, incident reporting, and lifecycle documentation.

    Get started

    Secure-by-Design Requirements for Digital Products

    Meet CRA cybersecurity requirements for software, hardware and connected products with unified controls, vulnerability management and automated documentation.

    • CRA security requirements in the Unified Control Library
    • Secure development and testing obligations
    • Vulnerability handling and coordinated disclosure
    • Evidence for SBOM and component dependencies
    • Support for class I and class II product requirements

    Secure-by-Design Lifecycle

    DesignSecurity Review
    DevelopmentCode Analysis
    TestingPen Testing
    ReleaseFinal Audit
    Security Gate Progress3 of 4

    Software Bill of Materials

    SBOM

    247

    Components

    12

    Direct Deps

    1

    Vulnerable

    PackageVersionStatus
    react18.2.0
    lodash4.17.21
    axios1.6.2
    express4.18.2

    Last scan: 2 hours ago

    Lifecycle Documentation and Compliance Evidence

    Maintain complete technical documentation for CRA compliance with automated governance workflows, evidence collection and audit trails.

    • Technical documentation aligned with CRA requirements
    • Governance workflows for approvals and versioning
    • Evidence for testing, updates and configuration
    • Policy alignment for development and release processes
    • Product lifecycle audit trails

    Vulnerability Management and Mandatory Reporting

    Automate CRA's vulnerability handling and incident notification requirements with structured workflows, disclosure processes and supply-chain oversight.

    • Vulnerability intake and disclosure workflows
    • Structured incident reporting
    • Evidence for patching and remediation
    • Governance Graph dependencies for digital products
    • Supplier and supply-chain cybersecurity checks

    Vulnerability Disclosure Workflow

    Intake

    CVE Reported

    Assign

    CVE-2024-XXX

    Patch

    In Progress

    Notify

    Pending

    Active Disclosures

    CVE-2024-31337High

    Authentication bypass in v2.1.0

    CVE-2024-28901Patched

    XSS in admin panel - resolved

    3

    Open

    12

    Resolved

    48h

    Avg. Time

    Ready to meet Cyber Resilience Act requirements?

    Join organisations using Basenorm to automate CRA security controls, vulnerability handling, documentation and supply-chain governance.

    Frequently Asked Questions

    Explore frequently asked questions about the Cyber Resilience Act and related compliance topics.