The fifteen governance controls your board needs for a Cyber Resilience Act audit, in language it can answer.
The Cyber Resilience Act (CRA) requires manufacturers of digital products to demonstrate cybersecurity across the whole product lifecycle. This checklist translates the CRA's governance requirements into fifteen concrete board questions with clear evidence patterns.
Whether your product is developed CRA-compliant is not decided in the conformity assessment, but in the design phase. The three controls of this area check whether risk thinking exists before the code.
Technical documentation under Annex VII must be kept for ten years. The three controls of this area check whether this documentation is alive, or whether it collapses as a facade at the first audit.
Vulnerability management is the domain where compliance becomes visible in real time. The three controls of this area check whether you are operational in an emergency.
The support period is the longest contractual obligation in the CRA. The three controls of this area check whether you can back this obligation with resources and processes.
Without a competent team, all other controls remain paper. The three controls of this area check whether the people who should produce the conformity have the prerequisites for it.
When a control is not yet in place, Inspector spots the gap directly in your Jira and delivers the signed template through Cronos.
Install Inspector for JiraThis website uses only strictly necessary cookies and privacy-friendly, cookieless analytics. Privacy