Skip to content

CRA readiness

How Craftifact supports CRA-relevant artifact, SBOM, vulnerability, and access workflows.

The EU Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, introduces cybersecurity requirements for products with digital elements. The CRA entered into force on 10 December 2024. Reporting obligations apply from 11 September 2026, and the main obligations apply from 11 December 2027.

For official context, see the European Commission CRA overview and the legal text on EUR-Lex.

Where Craftifact helps

Craftifact supports technical workflows that are relevant for software manufacturers preparing for CRA obligations:

  • controlled artifact repositories for Maven, npm, Python, OCI/Docker, and Go packages
  • CycloneDX SBOM upload and generated SBOM support for selected hosted content
  • SBOM binding to package artifacts and OCI digests
  • dependency and component visibility from SBOM data
  • vulnerability reports tied to effective SBOMs
  • suppression records with expiry and justification for accepted risk
  • technical evidence snapshots and exports for explicit package artifact and OCI subject sets
  • OIDC, RBAC, groups, robot accounts, and scoped tokens for controlled access
  • APIs for artifact lookup, SBOM upload, vulnerability report automation, and evidence bundle export

Evaluation checklist

Teams evaluating CRA readiness usually need answers to practical questions:

  • Can we identify which artifacts and components belong to a release?
  • Can we attach or generate SBOMs for relevant artifacts?
  • Can we review known vulnerabilities against the SBOM that actually applies?
  • Can we record why a finding was accepted, deferred, or suppressed?
  • Can we prove who can publish, read, or automate access to repositories?
  • Can we export a technical evidence bundle for an explicit package artifact or OCI subject set?
  • Can we use APIs to retrieve relevant artifact, SBOM, vulnerability, and evidence data instead of relying on screenshots?

Craftifact is designed to make these workflows visible and repeatable inside the artifact repository.

For a more operational review path, use the CRA workflow evaluator checklist.

Useful documentation

What Craftifact does not replace

Craftifact does not provide legal advice or a complete regulatory compliance outcome. It does not replace product risk assessment, secure product design, conformity assessment, regulatory product marking, coordinated vulnerability disclosure policy ownership, security-event reporting, or update delivery to users.

Use Craftifact as a technical building block for artifact, SBOM, vulnerability, access, and evidence-export workflows. Final legal and compliance decisions remain with your organization and its advisors.

Talk to us

If you are evaluating Craftifact for CRA preparation, contact us with your package formats, SBOM workflow, vulnerability triage process, and audit-support needs.