Reviewed 17 August 2026
CRA compliance checklist for 2026
Nine work packages, in the order small teams usually have to do them. Reporting readiness sits first because it is the obligation that arrives first and cannot be written up retrospectively.
Last updated · Written and reviewed by Jonatan Tensetti · Tensetti Tools
Use this as a planning instrument. Each line is something you can assign an owner and a date to. Where a line is genuinely uncertain, record it as an open question rather than marking it done — an honest gap list is worth more than a green dashboard.
| # | Work package | Done when |
|---|---|---|
| 1 | Scope decision, written down | You can name every product with digital elements you place on the EU market, and your role for each one, with a dated note explaining the decision. |
| 2 | Reporting readiness (from 11 Sep 2026) | A named owner and deputy can produce an early warning within 24 hours and a notification within 72 hours, with access to the reporting platform arranged in advance. |
| 3 | Awareness definition | Your organisation has agreed what starts the clock: which signals count, who they reach, and how the time is recorded. |
| 4 | Vulnerability handling process | You can identify and document vulnerabilities, remediate without delay, test fixes, and distribute security updates to users. |
| 5 | Coordinated disclosure policy | A published policy with a contact address, expected response times and a safe-harbour statement. |
| 6 | Support period, stated publicly | A defined and communicated support period, with the reasoning behind its length recorded. |
| 7 | SBOM and component inventory | You can list top-level dependencies per released version and answer a supplier question within a working day. |
| 8 | Technical documentation and risk assessment | A cybersecurity risk assessment per product and documentation kept current across releases. |
| 9 | Conformity route for December 2027 | You know whether your product is default, important or critical, and which assessment route follows from that. |
The three lines that fail most often
Awareness. Teams write "24 hours from awareness" into a policy without ever deciding whose awareness counts. A support inbox that nobody reads on a Saturday is still awareness in practice; decide now, not during an incident.
Platform access. Access, credentials and entity registration are not things to discover at hour one. Treat them as prerequisites and see the reporting platform preparation guide.
Deputies. A single named owner is a single point of failure. Every reporting role needs a deputy with the same access and the same authority to send.
How to use this before an audit or a customer questionnaire
Rehearse the reporting flow once with fictional data, keep the resulting gap list, and attach dates and owners to it. A dated exercise record plus an honest remediation plan answers a supplier questionnaire far better than a claim of full compliance you cannot evidence.
Reviewed 17 August 2026 · assessment version 1.0.0
Frequently asked questions
- What should a small manufacturer do first for the CRA?
- Confirm whether your product counts as a product with digital elements placed on the EU market, then name the people who own reporting, product data and approval. Scope and ownership block everything else.
- Which CRA dates matter in 2026?
- Reporting obligations start on 11 September 2026 and general application follows on 11 December 2027. Plan the reporting flow against the earlier date.
- Do we need a vulnerability disclosure policy?
- A coordinated disclosure route is part of being a credible manufacturer, and customers increasingly ask for it in questionnaires. A one-page policy with a monitored contact address is enough to start.
- How do we evidence readiness to a customer or auditor?
- A dated tabletop exercise, the gap list it produced, and owners and dates against each gap answers a questionnaire far better than an unsupported claim of full compliance.