The situation
A software supplier can publish a patch but has not documented how customers verify it or receive it without avoidable delay. The record needs to connect distribution security, automatic-update provisions where applicable, user information and the responsible product owner.
Facts that change the answer
- How is an update authenticated and delivered securely?
- Are applicable automatic-update and user-control requirements addressed?
- Are delivery timing and charging conditions documented?
Compare the worked results
These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.
Secure update distribution not confirmed
Hypothetical example 1
Key facts in this example
- Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
- No
- An accountable product owner reviewed the completeness of this readiness record
- Yes
All recorded assumptions (22)
- Product with digital elements
- Hypothetical example product
- A documented cybersecurity risk assessment covers the product as a whole and remains updated
- Yes
- The product is designed, developed and produced to an appropriate cybersecurity level based on its risks
- Yes
- The release process checks that the product is made available without known exploitable vulnerabilities
- Yes
- Secure default configuration and a way to reset to the original state are addressed where applicable
- Yes
- Protection from unauthorised access through appropriate control mechanisms is addressed
- Yes
- Confidentiality of stored, transmitted and otherwise processed data is protected where applicable
- Yes
- Integrity of data, commands, programs and configuration is protected, and corruption is reported where appropriate
- Yes
- Only data adequate, relevant and limited to the product’s intended purpose is processed where applicable
- Yes
- Essential and basic functions remain available after an incident, including resilience and recovery measures where applicable
- Yes
- Measures minimise negative impact, attack surfaces and unnecessary externally accessible interfaces
- Yes
- Security-relevant activity can be recorded or monitored with an appropriate opt-out where required
- Yes
- Users are notified of available security updates, receive clear information after updates, and automatic security updates are enabled by default with an opt-out and recommended alternative mechanism where applicable
- Yes
- Users can securely and permanently remove their data and settings and, where applicable, transfer them to another product
- Yes
- Vulnerabilities and components are identified and documented, including an appropriate software bill of materials record
- Yes
- Vulnerabilities are addressed and remediated without delay, including through security updates where appropriate
- Yes
- Regular effective tests and reviews support product security and vulnerability handling
- Yes
- Information about fixed vulnerabilities, including description, identification, severity and impact where applicable, is published without undermining legitimate security interests
- Yes
- A coordinated vulnerability-disclosure policy is enforced and measures facilitate reporting and sharing information about vulnerabilities in the product and its third-party components, including a contact address
- Yes
- Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
- No
- Technical documentation, EU declaration, support information and Annex II user information are assembled
- Yes
- An accountable product owner reviewed the completeness of this readiness record
- Yes
Controls recorded but owner review missing
Hypothetical example 2
Key facts in this example
- Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
- Yes
- An accountable product owner reviewed the completeness of this readiness record
- No
All recorded assumptions (22)
- Product with digital elements
- Hypothetical example product
- A documented cybersecurity risk assessment covers the product as a whole and remains updated
- Yes
- The product is designed, developed and produced to an appropriate cybersecurity level based on its risks
- Yes
- The release process checks that the product is made available without known exploitable vulnerabilities
- Yes
- Secure default configuration and a way to reset to the original state are addressed where applicable
- Yes
- Protection from unauthorised access through appropriate control mechanisms is addressed
- Yes
- Confidentiality of stored, transmitted and otherwise processed data is protected where applicable
- Yes
- Integrity of data, commands, programs and configuration is protected, and corruption is reported where appropriate
- Yes
- Only data adequate, relevant and limited to the product’s intended purpose is processed where applicable
- Yes
- Essential and basic functions remain available after an incident, including resilience and recovery measures where applicable
- Yes
- Measures minimise negative impact, attack surfaces and unnecessary externally accessible interfaces
- Yes
- Security-relevant activity can be recorded or monitored with an appropriate opt-out where required
- Yes
- Users are notified of available security updates, receive clear information after updates, and automatic security updates are enabled by default with an opt-out and recommended alternative mechanism where applicable
- Yes
- Users can securely and permanently remove their data and settings and, where applicable, transfer them to another product
- Yes
- Vulnerabilities and components are identified and documented, including an appropriate software bill of materials record
- Yes
- Vulnerabilities are addressed and remediated without delay, including through security updates where appropriate
- Yes
- Regular effective tests and reviews support product security and vulnerability handling
- Yes
- Information about fixed vulnerabilities, including description, identification, severity and impact where applicable, is published without undermining legitimate security interests
- Yes
- A coordinated vulnerability-disclosure policy is enforced and measures facilitate reporting and sharing information about vulnerabilities in the product and its third-party components, including a contact address
- Yes
- Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
- Yes
- Technical documentation, EU declaration, support information and Annex II user information are assembled
- Yes
- An accountable product owner reviewed the completeness of this readiness record
- No
Evaluated on 2026-09-13 using EU Cyber Resilience Act essential cybersecurity requirements readiness checklist, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.
Evidence to keep
- Signed-release and distribution process
- Update behaviour tests and user instructions
- Applicable delivery terms and owner approval
Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.
Your next step
Test the release-to-user path and close the recorded delivery gap. Keep actual SBOMs and technical files in their managed systems and reference them from the assessment.
Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.
Sources and application dates
- Regulation (EU) 2024/2847 (Cyber Resilience Act)Article 13; Annex I Parts I and II; Annexes II and VII
- European Commission CRA implementation guidance (2026)Sections 7–8 — product variants, remote data processing and risk assessment
Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.
These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.