Skip to main content

    Cyber Resilience Act for Software and Connected Products

    Basenorm centralises CRA obligations including secure development, vulnerability handling, incident reporting, and lifecycle documentation.

    Get started

    Secure-by-Design Requirements for Digital Products

    Meet CRA cybersecurity requirements for software, hardware and connected products with unified controls, vulnerability management and automated documentation.

    • CRA security requirements in the Unified Control Library
    • Secure development and testing obligations
    • Vulnerability handling and coordinated disclosure
    • Evidence for SBOM and component dependencies
    • Support for class I and class II product requirements

    Secure-by-Design Lifecycle

    DesignSecurity Review
    DevelopmentCode Analysis
    TestingPen Testing
    ReleaseFinal Audit
    Security Gate Progress3 of 4

    Software Bill of Materials

    SBOM

    247

    Components

    12

    Direct Deps

    1

    Vulnerable

    PackageVersionStatus
    react18.2.0
    lodash4.17.21
    axios1.6.2
    express4.18.2

    Last scan: 2 hours ago

    Lifecycle Documentation and Compliance Evidence

    Maintain complete technical documentation for CRA compliance with automated governance workflows, evidence collection and audit trails.

    • Technical documentation aligned with CRA requirements
    • Governance workflows for approvals and versioning
    • Evidence for testing, updates and configuration
    • Policy alignment for development and release processes
    • Product lifecycle audit trails

    Vulnerability Management and Mandatory Reporting

    Automate CRA's vulnerability handling and incident notification requirements with structured workflows, disclosure processes and supply-chain oversight.

    • Vulnerability intake and disclosure workflows
    • Structured incident reporting
    • Evidence for patching and remediation
    • Governance Graph dependencies for digital products
    • Supplier and supply-chain cybersecurity checks

    Vulnerability Disclosure Workflow

    Intake

    CVE Reported

    Assign

    CVE-2024-XXX

    Patch

    In Progress

    Notify

    Pending

    Active Disclosures

    CVE-2024-31337High

    Authentication bypass in v2.1.0

    CVE-2024-28901Patched

    XSS in admin panel - resolved

    3

    Open

    12

    Resolved

    48h

    Avg. Time

    Ready to meet Cyber Resilience Act requirements?

    Join organisations using Basenorm to automate CRA security controls, vulnerability handling, documentation and supply-chain governance.

    Frequently Asked Questions

    Explore frequently asked questions about the Cyber Resilience Act and related compliance topics.

    We use cookies to improve your experience and analyse site traffic. By clicking "Accept All", you consent to analytics cookies. Privacy Policy