CRA reporting and readiness operations

Make the operational record behind CRA readiness reviewable.

CRA Ledger helps manufacturers connect Product-Version evidence with human reporting decisions, milestone tracking, external references, and retained history.

Operational context

CRA readiness is a continuing product-security operating problem.

The Act introduces lifecycle, vulnerability-handling, documentation, and reporting expectations. The practical challenge is keeping the supporting record current as products and vulnerabilities change.

10 December 2024

CRA entered into force

The EU Cyber Resilience Act entered into force and began the transition toward application.

11 September 2026

Reporting obligations apply

Reporting obligations apply for actively exploited vulnerabilities and severe incidents in scope.

11 December 2027

Main obligations apply

The main product-security and lifecycle obligations apply across products with digital elements in scope.

Timeline information is provided for orientation and is not legal advice. Confirm current obligations and scope with qualified counsel.

What teams need to operate

A clear record across evidence, decisions, and reporting milestones.

CRA Ledger focuses on the operational information teams need to collect, review, retain, and revisit.

Product-Version evidence continuity

Keep SBOM scope, findings review, decisions, release sign-off, and retained evidence connected to the affected release.

Human assessment and milestones

Record the determination, rationale, reviewer, awareness timestamp, and milestone state without turning legal judgment into an automated claim.

External references and corrective measures

Retain submission references and timestamps, record when a corrective measure is available, and preserve close/reopen history.

Audit trail and ownership

Keep changes, decisions, owners, roles, and activity visible to the teams responsible for the workflow.

Connected reporting workflow

Record the case without pretending the platform is the authority.

When a vulnerability or incident may require reporting, teams can connect the case to a Product Version and preserve the operational trail around it.

Humans remain responsible for legal judgment, reportability determination, compliance interpretation, and external submission.
1

Security event / vulnerability

Start from a Product Version and source context

2

Awareness timestamp

Record when the team became aware

3

Human determination

Record reportable, not reportable, or needs review

4

Reporting milestones

Track required deadlines and milestone state

5

External submission record

Retain references and submission timestamps

6

Corrective measure

Record when a corrective measure is available

7

Close / reopen history

Preserve the reason and decision trail

What CRA Ledger records

Evidence, timestamps, decisions, milestone state, and history.

Teams can record the awareness timestamp used for a reporting case.
Human users can record a reportable, not reportable, or needs-review determination.
Milestones can be tracked with due dates, status, and submission timestamps.
External submission references and supporting evidence references can be retained.
Corrective-measure availability and close/reopen history remain part of the case record.

Important boundary

Workflow support is not legal certification.

CRA Ledger supports readiness preparation by organizing evidence and workflow history. It does not certify compliance, determine legal reportability automatically, submit reports to authorities, replace conformity assessment, or guarantee that a product satisfies CRA obligations.

See how the Product-Version workflow works

Further reading

Use the official text and qualified advice for legal interpretation.

This page explains the operational problem CRA Ledger is designed to support. It is not a substitute for the Regulation, official guidance, or advice from qualified legal and compliance professionals.

Next step

Map one Product Version to a reviewable CRA workflow.

Bring one release, its SBOM, and the evidence questions your team needs to answer.