Showing posts with label Compliance Checklist. Show all posts
Showing posts with label Compliance Checklist. Show all posts

Saturday, August 29, 2026

Your Complete Cyber Resilience Act Compliance Checklist for 2026: An 8-Step Guide for Manufacturers

Cybersecurity professional reviewing a Cyber Resilience Act compliance dashboard showing the complete CRA compliance checklist for digital products.

The cyber resilience act compliance checklist is now a top priority for every digital product manufacturer selling into the EU. This guide walks you through all eight steps - from product classification to CE marking. We cover essential cybersecurity requirements, vulnerability handling, conformity assessment, and automation strategies so you can meet CRA compliance requirements 2026 with confidence and zero last-minute surprises.

What Is the EU Cyber Resilience Act and Why Does It Matter

The cyber resilience act compliance checklist sits at the heart of the biggest shift in EU product cybersecurity regulation in a decade. The Cyber Resilience Act (CRA) is the European Union's landmark law that forces manufacturers to build security into every connected product. It applies to hardware, software, and firmware sold on the EU market.

Before the CRA, European cybersecurity legislation for IoT lacked teeth. Products could ship with default passwords, unpatched vulnerabilities, and zero long-term support. That era is now ending. The CRA creates clear digital product security obligations that every manufacturer must meet - or face steep penalties.

We believe this regulation changes the game. It shifts responsibility from the consumer to the maker. And it demands proof, not promises.

Which Products Fall Under the CRA

The CRA covers any product with digital elements that connects to a network or device. This includes smart home gadgets, industrial sensors, SaaS platforms, mobile apps, and operating systems. If your product processes or transmits data, it likely falls within scope.

Open-source software used in commercial products is included too. But purely non-commercial open-source projects get certain exemptions. The key test is whether the product reaches the EU market for a commercial purpose.

Default Category vs Annex III Class I and Class II

Most products fall into the default category. These carry lower risk and allow a simpler path to compliance. Annex III lists two higher-risk classes.

Development team implementing secure-by-design practices with automated vulnerability scanning and SBOM generation.

Class I includes products like password managers, VPNs, and network management tools. Class II covers critical items such as firewalls, intrusion detection systems, and industrial control systems. The class of your product determines the type of conformity assessment CRA requires.

Dec 2024 Entry, Sep 2026 Reporting, Dec 2027 Full Enforcement

The CRA entered into force in December 2024. But full enforcement rolls out in phases. By September 2026, manufacturers must begin reporting actively exploited vulnerabilities to ENISA. By December 2027, all CRA compliance requirements 2026 and beyond take full legal effect.

This timeline gives teams roughly two years to prepare. However, we strongly recommend starting now. Building a proper cyber resilience act compliance checklist takes time - especially for complex product lines.

The Complete Cyber Resilience Act Compliance Checklist

Here is the step-by-step cyber resilience act compliance checklist we recommend to every manufacturer. These CRA compliance steps for digital products cover classification, security design, documentation, and market access.

Step 1 - Product Classification Under Annex II and Annex IV

First, classify your product. Check Annex II for the list of important digital products (Class I) and critical digital products (Class II). Then review Annex IV to understand which conformity route applies.

If your product does not appear in Annex III, it falls under the default category. This is good news because default products allow self-assessment. Getting this step right early saves you months of confusion later.

Step 2 - Map Essential Cybersecurity Requirements to Your Product

The CRA defines a set of essential cybersecurity requirements in Annex I. These cover areas like access control, data protection, secure defaults, and integrity safeguards.

We map each requirement to specific product features and controls. This is where a risk assessment for connected products becomes critical. You need to identify threats, rate their severity, and show how your design mitigates each one. This step forms the backbone of your cyber resilience act compliance checklist.

Step 3 - Establish a Vulnerability Handling Process

The CRA demands a clear, documented vulnerability handling process. You must accept and triage vulnerability reports. You must issue security patches promptly. And you must notify ENISA of any actively exploited vulnerability within 24 hours.

On top of that, your security update obligations require you to provide free security updates for the expected product lifetime - or at least five years, whichever is shorter. We recommend building an internal response team and testing your process with tabletop exercises.

Step 4 - Generate and Maintain a Software Bill of Materials (SBOM)

Every product needs a machine-readable SBOM. This document lists all third-party components, libraries, and dependencies in your software. It helps you track known vulnerabilities across your supply chain.

We use automated tools to generate SBOMs during the build process. Keeping the SBOM updated after each release is a core post-market surveillance requirement. Regulators and customers may request it at any time.

Step 5 - Implement Secure-by-Design Development Practices

Security cannot be an afterthought. The CRA requires manufacturers to bake security into the entire product lifecycle. That means threat modeling during design, secure coding standards during development, and penetration testing before release.

We integrate security gates into every sprint. This approach reduces rework and builds a strong evidence trail. It also aligns with how to comply with the cyber resilience act at its core - by proving security is part of your DNA, not just a checkbox.

Step 6 - Prepare Technical Documentation and EU Declaration of Conformity

You must create detailed technical documentation that proves your product meets every essential requirement. This includes design specs, test results, risk assessments, and your SBOM.

You also need to draft an EU Declaration of Conformity. This is a formal statement that your product satisfies CRA rules. We keep these documents version-controlled and audit-ready at all times. This step alone can make or break your cyber resilience act compliance checklist.

Step 7 - Conduct or Commission the Conformity Assessment

The type of assessment depends on your product's classification. Default-category products can follow a self-assessment path using harmonized standards. Class I and Class II products face stricter requirements.

Self-Assessment vs Third-Party (Notified Body) Audits

Default products may use internal assessment - sometimes called Module A. Class I products can self-assess only if they follow a harmonized European standard or meet specific conditions. Otherwise, a third-party notified body must review them.

Class II products always require a notified body audit. We help teams prepare audit packages that satisfy notified body expectations the first time. Understanding the conformity assessment CRA process early prevents delays and surprise costs.

Step 8 - Affix the CE Mark and Register

Once you pass assessment, you can affix the CE mark to your product. This signals compliance with EU regulations, including CE marking cybersecurity rules under the CRA.

Visual workflow illustrating the complete Cyber Resilience Act compliance process from product classification to CE marking.
You must also register the product in the relevant EU database. After registration, your manufacturer obligations under CRA continue. You must monitor the product, handle vulnerabilities, and issue updates throughout its lifecycle.


Cyber Resilience Act Compliance Checklist - At a Glance

Here is a comparison table that shows the CRA compliance requirements 2026 by product class:

Compliance Factor

Default Category

Class I (Annex III)

Class II (Annex III)

Risk Level

Low

Important

Critical

Conformity Assessment

Self-assessment (Module A)

Self-assessment (if standards apply) or third-party

Third-party notified body required

SBOM Required

Yes

Yes

Yes

Vulnerability Reporting to ENISA

24-hour deadline

24-hour deadline

24-hour deadline

Security Updates

Minimum 5 years or product lifetime

Minimum 5 years or product lifetime

Minimum 5 years or product lifetime

Technical Documentation

Required

Required (more detailed)

Required (most detailed)

CE Marking

Required

Required

Required

Example Products

Consumer IoT, basic apps

Password managers, VPNs, routers

Firewalls, smartcard readers, industrial control systems

Full Enforcement Date

December 2027

December 2027

December 2027


Penalties for Non-Compliance - What Manufacturers Risk

The CRA carries serious penalties. Ignoring your EU cyber resilience act checklist for manufacturers is not an option.

Fines Up to €15M or 2.5% of Global Turnover

Non-compliance with essential cybersecurity requirements can trigger fines up to €15 million or 2.5% of annual worldwide turnover - whichever is higher. Smaller violations may still cost up to €10 million or 2%.

These numbers match the scale of GDPR fines. We have seen regulators across the EU become more aggressive with enforcement in 2025 and into 2026. Waiting until the deadline is a risky bet.

Product Bans and Market Withdrawal Scenarios

Beyond fines, authorities can order product recalls or ban products from the EU market entirely. If your product fails to meet its digital product security obligations, market surveillance authorities can act fast.

A product ban can destroy customer trust overnight. We always tell our clients: the cost of compliance is a fraction of the cost of a market withdrawal. Building your cyber resilience act compliance checklist now protects both your revenue and your reputation.

How to Automate CRA Compliance End to End

Manual compliance tracking breaks down at scale. That is exactly why we built UbiComply.ai. Automation turns a painful process into a smooth workflow.

Using a CRA Control Matrix to Track Progress

We map every CRA requirement to a control inside our platform. Each control has an owner, evidence links, and a status tracker. This gives leadership a real-time dashboard of their cyber resilience act compliance checklist progress.

A control matrix also simplifies audits. When a notified body asks for proof, you pull it from one place - not from scattered spreadsheets and email threads.

Compliance automation dashboard providing continuous Cyber Resilience Act monitoring, evidence collection, and audit readiness.

CI/CD-Integrated Scanning for Continuous Proof

We connect directly to your CI/CD pipeline. Every code commit triggers automated security scans, SBOM generation, and compliance checks. This approach delivers continuous proof of compliance - not just a snapshot from months ago.

Continuous compliance is the future. It reduces audit fatigue and catches issues before they reach production. Above all, it aligns perfectly with how to comply with the cyber resilience act in an agile development environment.

Common Mistakes to Avoid

Even well-prepared teams stumble. Here are pitfalls we see repeatedly:

Waiting for harmonized standards. Many teams pause until standards are finalized. But the CRA applies regardless. Start with Annex I requirements now and adapt later.

Ignoring the SBOM. Teams that skip SBOM generation early face painful catch-up work. Start generating SBOMs from day one.

Treating CRA as a one-time project. The CRA demands ongoing post-market surveillance requirements. Compliance is continuous, not a finish line.

Confusing CRA with NIS2. The CRA targets products. NIS2 targets organizations and critical infrastructure operators. Both matter, but they cover different ground.

FAQ

What is the Cyber Resilience Act in simple terms?

The CRA is an EU law that requires all digital products sold in Europe to meet minimum cybersecurity standards. It makes manufacturers responsible for security throughout a product's life.

Who needs to comply with the CRA?

Any manufacturer, importer, or distributor placing a product with digital elements on the EU market. This covers hardware, software, and connected devices. Your cyber resilience act compliance checklist applies whether you are based inside or outside the EU.

When does the Cyber Resilience Act come into force?

It entered into force in December 2024. Vulnerability reporting obligations begin in September 2026. Full enforcement starts in December 2027.

Is the CRA the same as CE marking for software?

Not exactly. The CRA adds cybersecurity to the CE marking process. Products that meet CRA requirements can carry the CE mark, showing they comply with this European cybersecurity legislation for IoT and digital products.

Can startups self-assess under the CRA?

Yes - if their product falls in the default category or qualifies under Class I with applicable harmonized standards. Class II products always need a third-party audit, regardless of company size.

What is the difference between CRA and NIS2?

The CRA focuses on product security. NIS2 focuses on organizational cybersecurity for essential and important entities. A manufacturer may need to follow both. They complement each other but serve different purposes within the EU's broader risk management and cybersecurity framework.

Conclusion

The cyber resilience act compliance checklist we outlined above gives you a clear, actionable roadmap. From product classification to CE marking, each step builds on the last. The CRA is not optional - and the deadlines are approaching fast.

We built UbiComply.ai to help manufacturers tackle exactly this challenge. Our platform automates control mapping, evidence collection, risk assessment for connected products, and audit readiness across the CRA and other frameworks like SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR, CMMC, and NIST.

Start your cyber resilience act compliance checklist today. The teams that prepare early will enter 2027 with confidence. The ones that wait will scramble. We are here to make sure you land in the first group.

UbiComply.ai - Compliance automation, cybersecurity governance, and audit readiness for the frameworks that matter most.




Monday, April 13, 2026

GDPR Compliance Checklist for SaaS: 15 Essential Steps to Protect Customer Data

 

Visual depicting a SaaS team responding to a data breach, assessing risks, notifying customers, and securing systems under GDPR compliance

In today’s digital landscape, protecting customer data is not just a best practice—it’s a legal requirement. The General Data Protection Regulation (GDPR) sets strict rules for businesses operating in the European Union (EU) or handling EU citizens’ data. Non-compliance can lead to hefty fines, reputational damage, and loss of customer trust. This GDPRchecklist will guide your SaaS company through the essential steps to safeguard customer information and stay compliant.

Understand GDPR Fundamentals

Before diving into compliance actions, it’s vital to grasp what GDPR is and why it matters. The regulation ensures that organizations handle personal data responsibly, giving individuals control over how their information is collected, stored, and processed. Key principles include:

  • ·       Lawfulness, fairness, and transparency: Data must be collected legally and used transparently.
  • ·       Purpose limitation: Data should only be used for specific, legitimate purposes.
  • ·       Data minimization: Collect only what is necessary.
  • ·       Accuracy: Ensure data is correct and up-to-date.
  • ·       Storage limitation: Retain data only as long as needed.
  • ·       Integrity and confidentiality: Protect data from breaches.
  • ·       Accountability: Demonstrate compliance with GDPR at all times.


Infographic showing GDPR principles for SaaS: lawfulness, purpose limitation, data minimization, accuracy, storage limitation, integrity, confidentiality, and accountability

Understanding these principles is the foundation of your GDPR compliance journey.

Appoint a Data Protection Officer (DPO)

A Data Protection Officer (DPO) oversees GDPR compliance and ensures your organization follows best practices. While mandatory for some companies, having a DPO—even voluntarily—demonstrates commitment to data protection. Their responsibilities include:

·       Monitoring GDPR compliance.

·       Conducting risk assessments.

·       Training staff on data protection.

·       Acting as a point of contact with regulatory authorities.

This step is crucial for maintaining accountability and proactive compliance.

Conduct a Data Audit

A thorough data audit identifies what customer data you collect, store, and process. Documenting this information is a critical part of the GDPR checklist because it allows you to:

Diagram showing a SaaS company’s data audit and flow, mapping collection, storage, and processing of personal customer data

·       Map data flows across your systems.

·       Identify unnecessary or redundant data.

·       Assess risks related to sensitive personal information.

Use this audit as a baseline for implementing privacy measures and updating your records for regulatory reporting.

Update Privacy Policies

Transparency is a cornerstone of GDPR compliance. Your privacy policy must clearly explain:

·       What data you collect.

·       Why you collect it.

·       How long you store it.

·       Who has access to it.

·       How users can exercise their rights.

Keep your language simple and straightforward—avoid legal jargon that confuses your customers. This builds trust and reduces the risk of complaints.

Obtain Explicit Consent

Under GDPR, explicit consent is required before processing personal data. This means customers must actively agree, rather than being automatically opted in. Best practices include:

·       Using clear, unambiguous consent forms.

·       Separating consent for different purposes.

·       Providing easy ways to withdraw consent.

Proper consent management ensures that your data collection is legal and respects customer autonomy.

Implement Privacy by Design

Privacyby design means integrating data protection into your products and services from the outset. Some steps to follow:

·       Encrypt sensitive customer data.

·       Limit access to only essential personnel.

·       Regularly test security measures.

·       Design systems that minimize data collection.

By adopting this proactive approach, you reduce the risk of breaches and demonstrate GDPR accountability.

Set Up a Data Breach Response Plan

Even with strong protections, breaches can happen. GDPR requires that companies report breaches within 72 hours. Your response plan should include:

·       Identifying and containing the breach quickly.

·       Assessing the impact on customer data.

·       Notifying affected individuals and regulators promptly.

·       Documenting all steps taken for accountability.

Being prepared can prevent fines and preserve customer confidence.

Manage Third-Party Vendors

Many SaaS companies rely on third-party services for storage, analytics, or marketing. Under GDPR, you are responsible for ensuring that these vendors also comply. Actions include:

·       Reviewing vendor contracts for GDPR clauses.

·       Conducting periodic audits of their security practices.

·       Limiting data sharing to only necessary information.

This step ensures that your compliance extends across the entire data ecosystem.

Facilitate Data Subject Rights

GDPR gives individuals several rights regarding their data, including:

·       Right to access their data.

·       Right to rectify errors.

·       Right to erasure (right to be forgotten).

·       Right to restrict processing.

·       Right to data portability.

·       Right to object to processing.

Implement clear processes for responding to these requests promptly, as failure to do so can result in penalties.

Encrypt and Secure Data

Technical safeguards are critical. Encrypting data both in transit and at rest ensures that personal information is protected even if systems are compromised. Additional measures include:

·       Multi-factor authentication for internal access.

·       Regular software updates and patching.

·       Firewalls and intrusion detection systems.

·       Secure backups and disaster recovery protocols.

Strong technical defenses are non-negotiable in a GDPR-compliant environment.

Conduct Regular Risk Assessments

Continuous monitoring and risk assessments help identify vulnerabilities before they become breaches. Steps include:

·       Mapping out potential data exposure points.

·       Evaluating the likelihood and impact of threats.

·       Implementing corrective measures.

Use these assessments to guide your compliance strategy and improve security protocols over time.

Train Your Team

Human error is a major source of data breaches. Regular staff training ensures everyone understands GDPR requirements and internal procedures. Training topics should include:

·       Data handling best practices.

·       Recognizing phishing attempts.

·       Reporting potential breaches.

·       Understanding customer rights under GDPR.

Empowered employees are your first line of defense.

Maintain Documentation

GDPR emphasizes accountability, which means keeping detailed records of:

·       Data processing activities.

·       Consent obtained from customers.

·       Data breach incidents and responses.

·       Third-party vendor compliance checks.

Comprehensive documentation demonstrates compliance to regulators and helps streamline audits.

Review and Update Policies Periodically

Compliance is not a one-time task. Regularly review policies, processes, and security measures to adapt to changing regulations, technologies, or business practices. Schedule reviews at least annually and after major system updates.

Monitor Regulatory Changes

GDPR evolves over time, and interpretations by EU regulators may shift. Stay informed about:

·       Updates from the European Data Protection Board (EDPB).

·       New guidance on consent, profiling, and cross-border data transfers.

·       Fines and enforcement trends.

Monitoring regulatory changes ensures your GDPR checklist stays relevant and your company remains compliant.

Conclusion

Implementing this GDPR checklist is essential for protecting customer data, avoiding penalties, and building trust with your users. By understanding GDPR fundamentals, auditing data, securing systems, and fostering a culture of compliance, your SaaS company can confidently navigate the complex regulatory landscape. Remember, GDPR is not just a legal obligation—it’s an opportunity to strengthen your relationship with customers and demonstrate your commitment to privacy.

By following these 15 steps, your organization will not only stay compliant but also set a standard for data protection excellence.

Your Complete Cyber Resilience Act Compliance Checklist for 2026: An 8-Step Guide for Manufacturers

The cyber resilience act compliance checklist is now a top priority for every digital product manufacturer selling into the EU. This guide w...