OpenChain provides CRA guidance with a Compliance Requirements & Checklist document.
The CRA (Regulation (EU) 2024/2847) establishes mandatory cybersecurity requirements for products with digital elements placed on the EU market. Organizations that develop, maintain, or distribute software with digital elements must ensure their products meet essential cybersecurity requirements throughout the product lifecycle.
The Cyber Resilience Act’s main obligations apply from 11 December 2027, with reporting obligations already applying as of 11 September 2026.
The OpenChain document defines the organizational compliance framework for the EU Cyber Resilience Act, structured in alignment with the OpenChain Project adoption framework and ISO/IEC 18974. It serves simultaneously as a policy framework and a self-certification checklist, covering program governance, SBOM quality, vulnerability handling, regulatory reporting (including the CRA Article 14 three-stage cascade), OSS stewardship, and technical file obligations.
Contributions welcome!
We’re excited to announce that the Release Candidate 1 of the OpenChain CRA Requirement & Checklist document is open for public comment until 08 September!
We warmly invite everyone to review the document and provide comments. Your input is crucial to ensure this checklist is comprehensive and repesents OpenChain community best-practice.
Contributions and feedback are welcome via multiple channels. Take a look at our review & contribution workflow.
For active discussion and feedback, everyone is invited to also join the Study Group meetings and the mailing list:
- Calendar
- Open Chain Business Operations Study Group EU/ASIA on Monday 11:00 UTC (bi-weekly)
- Open Chain Business Operations Study Group NA/EU (CRA Checklist focus) on Tuesday 14:00 UTC
- Mailing list