Skip to the content.

OpenChain CRA Compliance Requirements & Checklist

The OpenChain CRA Compliance Requirements & Checklist is a community-maintained, OpenChain-aligned self-certification and readiness resource for organizations preparing for EU Cyber Resilience Act obligations.

The Cyber Resilience Act’s main obligations apply from 11 December 2027, with reporting obligations already applying as of 11 September 2026.

The checklist is mapped to Regulation (EU) 2024/2847 and aligned with ISO/IEC 18974, ISO/IEC 5230, and relevant SBOM guidance including BSI TR-03183. It covers governance, product assessment, SBOM quality, vulnerability handling, regulatory reporting, OSS stewardship, technical-file evidence, security updates, and supply-chain obligations.

Current review status

Release Candidate 1 remains available for public review, and accepted pre-1.0 changes are staged in the OpenChain CRA Compliance GitHub repository.

Supporting registers

Discussion

For active discussion and feedback, everyone is invited to join the Study Group meetings and mailing list: