MISAK SYSTEMS

T-03EU Cyber Resilience Act · Reporting obligationsEarly access

Be ready to report under the CRA before you have something to report.

CRA Incident Readiness helps small software and digital product makers get their house in order for the Cyber Resilience Act reporting obligations: which components you ship, who your security contacts are, where the evidence would come from, and what is missing, mapped into one readiness pack.

HU · Kis szoftver- és digitálistermék-gyártóknak: feltérképezi a komponenseket, biztonsági kapcsolattartókat, bizonyítékforrásokat és hiányokat a Cyber Resilience Act bejelentési kötelezettségeihez.

Spec
RegulationCyber Resilience Act, Regulation (EU) 2024/2847
Reporting obligationsApply from 11 September 2026
ForSmall makers of software and products with digital elements
OutputReadiness pack with gaps and owners
NOTICE

Operational tooling, not legal advice. The readiness pack organises your components, contacts, evidence sources and gaps. Whether and how the CRA applies to your product, and what you must report, are legal questions for your counsel.

1Problem

When an incident happens, the clock is already running

  • 1.1Nobody is sure which third-party components and versions are inside each product you have on the market.
  • 1.2There is no agreed security contact, intake address or on-call owner for vulnerability reports.
  • 1.3Logs, release records and customer lists that a report would rely on live in different tools, or nowhere.
  • 1.4Small teams find the gaps for the first time in the middle of a real incident.

2How it works

  1. IN

    product

    URL, repository, short questionnaire

  2. 01

    component map

    from dependency manifests

  3. 02

    contacts + evidence

    security.txt, releases, logs

  4. 03

    gap analysis

    ordered by effort and impact

  5. OUT

    readiness pack

    gap list, runbook skeleton

Fig. 1 — CRA Incident Readiness pipeline
  1. 2.1

    Tell us about your product

    Product URL or repository, and a short questionnaire about releases, support and contacts. No production access needed.

  2. 2.2

    Automated mapping

    We read dependency manifests, public security pages (such as security.txt) and release information to map components, contacts and evidence sources.

  3. 2.3

    Readiness pack and gap list

    You get a structured pack with what is in place, what is missing, and a short prioritised list of next steps.

cra-ready scan https://github.com/acme/widgetExample output · illustrative data
$ cra-ready scan https://github.com/acme/widgetmanifests: package-lock.json, requirements.txt components mapped             142                                    OKsecurity.txt                  not found at /.well-known/security.txt GAPvulnerability contact         none published                         GAPrelease records               GitHub releases (23)                   OKincident owner / on-call      not defined (questionnaire)            GAP gaps: 3 · pack: cra-readiness-acme-widget.pdf

3Deliverables

3.1

Component map

Components and versions found in your manifests, as a starting point for an SBOM.

3.2

Security contact check

Whether a reachable vulnerability-reporting contact is published (for example security.txt) and who owns it.

3.3

Evidence source map

Where the information an incident report needs would come from: logs, releases, affected customers, timelines.

3.4

Gap list

What is missing, ordered by effort and impact, written for a small team.

3.5

Incident runbook skeleton

A fill-in-the-blanks internal runbook: who does what, in what order, using which sources.

3.6

Official references

Links to the Commission's CRA pages so your counsel can check the obligations against your product.

4Pricing

Free readiness scan

€0

One product, public information only.

  • Security contact check
  • Top-level component overview
  • First gaps found

Readiness pack

from €49

The full pack for one product.

  • Component map and gap list
  • Evidence source map
  • Incident runbook skeleton

Early access price. Larger product portfolios are quoted before any work starts.

Early access prices, excl. any applicable VAT. No payment is taken on this site.

5FAQ

Is this legal advice?

No. It is operational tooling that organises facts about your product and your processes. Whether the CRA applies to your product and what exactly you must report is for your legal counsel to confirm.

When do the CRA reporting obligations apply?

According to the European Commission, the CRA's reporting obligations apply from 11 September 2026, while most other requirements apply later. See the Commission's Cyber Resilience Act page for the official timeline.

Do you need access to my systems?

No production access. A repository or dependency manifests and a short questionnaire are enough. Private repositories are read only with access you grant.

Who is it for?

Small software companies, independent developers and makers of connected or digital products who do not have a dedicated security or compliance team.

Does it produce a full SBOM?

It produces a component map from your manifests, which is a practical starting point. A complete, signed SBOM for every build is a separate step we can discuss.

7Request

Request the free scan

Tell me where to look. You get the free result first and decide afterwards whether the paid deliverable is worth it.

Built and run by Misak Systems (Ottó Misák, software engineer) · Hungary, EU

Operational tooling, not legal advice.

Privacy: we only use your name, email and URL to reply and run the requested scan. No newsletter, no reselling, no tracking pixels. Private repositories are only accessed with access you explicitly grant.