OpenChain CRA Compliance Requirements & Checklist
The OpenChain CRA Compliance Requirements & Checklist is a community-maintained, OpenChain-aligned self-certification and readiness resource for organizations preparing for EU Cyber Resilience Act obligations.
The Cyber Resilience Act’s main obligations apply from 11 December 2027, with reporting obligations already applying as of 11 September 2026.
The checklist is mapped to Regulation (EU) 2024/2847 and aligned with ISO/IEC 18974, ISO/IEC 5230, and relevant SBOM guidance including BSI TR-03183. It covers governance, product assessment, SBOM quality, vulnerability handling, regulatory reporting, OSS stewardship, technical-file evidence, security updates, and supply-chain obligations.
Current review status
Release Candidate 1 remains available for public review, and accepted pre-1.0 changes are staged in the OpenChain CRA Compliance GitHub repository.
Supporting registers
Discussion
For active discussion and feedback, everyone is invited to join the Study Group meetings and mailing list:
- Calendar
- OpenChain Business Operations Study Group EU/ASIA on Monday 11:00 UTC (bi-weekly)
- OpenChain Business Operations Study Group NA/EU (CRA Checklist focus) on Tuesday 14:00 UTC
- Mailing list