Skip to main content
CRA

Meet the EU
Cyber Resilience Act

The CRA introduces mandatory cybersecurity requirements for hardware and software products with digital elements placed on the EU market. Basenorm centralises CRA obligations across the full product lifecycle, from secure development and vulnerability handling to SBOM management, conformity assessment and incident reporting.

Secure Development and Product Scope

Classify your products against CRA categories, define essential cybersecurity requirements, and maintain secure-by-design evidence mapped to the Unified Control Library.

  • Product scoping for important and critical digital products
  • Secure-by-design and secure-by-default controls
  • Alignment with essential cybersecurity requirements in Annex I
  • Technical documentation linked to the Unified Control Library
  • Integration with ISO 27001 and NIS2 controls

Secure-by-Design Lifecycle

DesignSecurity Review
DevelopmentCode Analysis
TestingPen Testing
ReleaseFinal Audit
Security Gate Progress3 of 4

Software Bill of Materials

SBOM

247

Components

12

Direct Deps

1

Vulnerable

PackageVersionStatus
react18.2.0
lodash4.17.21
axios1.6.2
express4.18.2

Last scan: 2 hours ago

Vulnerability Handling and SBOM Management

Operate a continuous vulnerability management programme, maintain a Software Bill of Materials for every product, and coordinate disclosure with ENISA and national CSIRTs.

  • SBOM generation and dependency tracking per product
  • Vulnerability intake, triage and remediation workflows
  • Coordinated disclosure aligned with ENISA guidance
  • Security updates and patch lifecycle documentation
  • Evidence trails for actively exploited vulnerability reporting

Conformity Assessment and CE Marking

Produce the technical file, run the appropriate conformity assessment route, and maintain CE marking evidence throughout the product's expected lifetime.

  • Technical file templates aligned with Annex V
  • Self-assessment and third-party assessment workflows
  • EU Declaration of Conformity management
  • Post-market surveillance and incident reporting
  • Governance Graph linkage between products, components and suppliers

Vulnerability Disclosure Workflow

Intake

CVE Reported

Assign

CVE-2024-XXX

Patch

In Progress

Notify

Pending

Active Disclosures

CVE-2024-31337High

Authentication bypass in v2.1.0

CVE-2024-28901Patched

XSS in admin panel - resolved

3

Open

12

Resolved

48h

Avg. Time

Ready to operationalise CRA compliance?

Join product manufacturers using Basenorm to manage secure development, SBOMs, vulnerability handling and conformity assessment in one governance platform.

Frequently Asked Questions

Explore frequently asked questions about the EU Cyber Resilience Act and related compliance topics.