Track A · Regulation
Cyber Resilience Act conformity
Determine your product class, meet the Annex I essential requirements, and build the technical documentation that supports CE marking and the EU declaration of conformity.
- 01Scope and classification against Annex III and Annex IV
- 02Annex I Part I product security requirements
- 03Annex I Part II vulnerability handling processes
- 04SBOM generation, depth, and maintenance
- 05Coordinated vulnerability disclosure policy
- 0624-hour and 72-hour reporting workflow to ENISA and CSIRTs
- 07Support period definition and security update delivery
- 08Conformity assessment route and notified body engagement
