CRA Compliance Checklist
EXPLORE MORE
EXPLORE MORE
How Sonatype helps you
The Cyber Resilience Act (CRA), covers all products with digital elements that can be connected to a device or a network.
The CRA includes eight annexes that provide detailed requirements and standards, including Essential Cybersecurity Requirements (Annex I) and Reporting Obligations of Manufacturers (Article 11). Only products that comply with these requirements will be allowed on the market. Technical documentation proving compliance is necessary, and imported products require a CE mark.
This checklist covers key elements of Annex I and Article 11, and how Sonatype can help support compliance throughout the SDLC.
Questions to consider when determining your preparedness to comply with CRA requirements
Risk Assessment |
---|
|
Risk Assessment
|
Incident Response |
---|
|
Incident Response
|
Data Protection |
---|
|
Data Protection
|
Standards and Policies |
---|
|
Standards and Policies
|
Access Control and Third-Parties |
---|
|
Access Control and Third-Parties
|
Reporting Obligations |
---|
|
Reporting Obligations
|
How Sonatype Can Help Optimise and Protect Your Software Supply Chain
Vulnerability scanning is central to the CRA, and only products that comply with the security and vulnerability management requirements above will be allowed on the market. Products will be presumed to be compliant, but sanctions will apply if they are discovered not to be. The Sonatype platform can help developers gather and report on compliance information, identify vulnerabilities, and meet the reporting requirements. To learn more about how we can help you ensure compliance, download our CRA User’s Guide to Compliance.
How Sonatype’s Platform helps you comply
Simplify SBOM Compliance and Security Monitoring with Sonatype SBOM Manager
More than 70 percent of Fortune 100 companies manage their software supply chains with Sonatype, and our SBOM Manager has been developed to take the uncertainty out of SBOM collection and monitoring compliance.