Product versions change.
Evidence has to follow release candidates, shipped versions, and updated SBOMs.
EU Cyber Resilience Act
The Cyber Resilience Act requires manufacturers to maintain documented evidence of cybersecurity processes across every product version. Full enforcement begins December 2027. CRA Ledger helps teams organize those workflows without replacing legal assessment.
CRA in brief
Applies to
manufacturers, importers, distributors of products with digital elements in the EU
Enforcement
December 2027 (reporting from September 2026)
Penalties
up to €15 million or 2.5% of annual global turnover
Timeline and penalty details are summarized for orientation. Read the CRA guide for source notes and official references.
CRA evidence problem
Product security evidence must stay current as products, vulnerabilities, remediation work, and review decisions change.
Evidence has to follow release candidates, shipped versions, and updated SBOMs.
Teams need a repeatable way to review new findings and preserve what happened.
Disposition, ownership, and remediation decisions should not live only in tickets.
Audit history, original uploads, and review activity need to remain reviewable over time.
Affected teams
CRA readiness work often spans commercial, security, engineering, and compliance teams. The product supports evidence organization without making legal determinations.
Maintain product-version evidence and security review history.
Coordinate product-security records without overstating legal conclusions.
Run vulnerability handling with retained review context.
Organize records for readiness reviews and customer evidence requests.
See what changed, what is blocked, and what needs action.
What CRA Ledger supports
CRA Ledger helps teams organize product-security evidence without making legal determinations.
Keep SBOMs, findings, decisions, and remediation context tied to the product version they belong to.
Upload or register CycloneDX/SPDX records and retain original artifact metadata for later review.
Track CVE review state, rationale, severity, ownership, and review activity.
Keep remediation updates, blocked work, and SLA pressure visible alongside findings.
Preserve user activity, review changes, imports, and evidence events for traceability.
Prepare product-security summaries for CRA readiness discussions without claiming legal certification.
Limitations
CRA Ledger supports operational readiness and evidence workflows. It does not provide legal advice, legal certification, notified body approval, or a replacement for formal legal/compliance assessment.
Next step
Review how SBOM intake, vulnerability handling, remediation status, and retained evidence fit your product portfolio.