Essential requirements

How should CRA readiness cover security-update delivery?

The update process needs evidence of secure distribution and the applicable delivery conditions. A working download button alone does not establish readiness.

Prepared by CRA Operations · Updated 2026-09-13 · Hypothetical worked examples

The situation

A software supplier can publish a patch but has not documented how customers verify it or receive it without avoidable delay. The record needs to connect distribution security, automatic-update provisions where applicable, user information and the responsible product owner.

Facts that change the answer

  • How is an update authenticated and delivered securely?
  • Are applicable automatic-update and user-control requirements addressed?
  • Are delivery timing and charging conditions documented?

Compare the worked results

These examples use the published assessment with the assumptions shown below. Change the facts in your own assessment before relying on its result.

Secure update distribution not confirmed

Hypothetical example 1

Assessment resultimplementation gaps remain
Key facts in this example
Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
No
An accountable product owner reviewed the completeness of this readiness record
Yes
All recorded assumptions (22)
Product with digital elements
Hypothetical example product
A documented cybersecurity risk assessment covers the product as a whole and remains updated
Yes
The product is designed, developed and produced to an appropriate cybersecurity level based on its risks
Yes
The release process checks that the product is made available without known exploitable vulnerabilities
Yes
Secure default configuration and a way to reset to the original state are addressed where applicable
Yes
Protection from unauthorised access through appropriate control mechanisms is addressed
Yes
Confidentiality of stored, transmitted and otherwise processed data is protected where applicable
Yes
Integrity of data, commands, programs and configuration is protected, and corruption is reported where appropriate
Yes
Only data adequate, relevant and limited to the product’s intended purpose is processed where applicable
Yes
Essential and basic functions remain available after an incident, including resilience and recovery measures where applicable
Yes
Measures minimise negative impact, attack surfaces and unnecessary externally accessible interfaces
Yes
Security-relevant activity can be recorded or monitored with an appropriate opt-out where required
Yes
Users are notified of available security updates, receive clear information after updates, and automatic security updates are enabled by default with an opt-out and recommended alternative mechanism where applicable
Yes
Users can securely and permanently remove their data and settings and, where applicable, transfer them to another product
Yes
Vulnerabilities and components are identified and documented, including an appropriate software bill of materials record
Yes
Vulnerabilities are addressed and remediated without delay, including through security updates where appropriate
Yes
Regular effective tests and reviews support product security and vulnerability handling
Yes
Information about fixed vulnerabilities, including description, identification, severity and impact where applicable, is published without undermining legitimate security interests
Yes
A coordinated vulnerability-disclosure policy is enforced and measures facilitate reporting and sharing information about vulnerabilities in the product and its third-party components, including a contact address
Yes
Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
No
Technical documentation, EU declaration, support information and Annex II user information are assembled
Yes
An accountable product owner reviewed the completeness of this readiness record
Yes

Controls recorded but owner review missing

Hypothetical example 2

Assessment resultmanagement review required
Key facts in this example
Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
Yes
An accountable product owner reviewed the completeness of this readiness record
No
All recorded assumptions (22)
Product with digital elements
Hypothetical example product
A documented cybersecurity risk assessment covers the product as a whole and remains updated
Yes
The product is designed, developed and produced to an appropriate cybersecurity level based on its risks
Yes
The release process checks that the product is made available without known exploitable vulnerabilities
Yes
Secure default configuration and a way to reset to the original state are addressed where applicable
Yes
Protection from unauthorised access through appropriate control mechanisms is addressed
Yes
Confidentiality of stored, transmitted and otherwise processed data is protected where applicable
Yes
Integrity of data, commands, programs and configuration is protected, and corruption is reported where appropriate
Yes
Only data adequate, relevant and limited to the product’s intended purpose is processed where applicable
Yes
Essential and basic functions remain available after an incident, including resilience and recovery measures where applicable
Yes
Measures minimise negative impact, attack surfaces and unnecessary externally accessible interfaces
Yes
Security-relevant activity can be recorded or monitored with an appropriate opt-out where required
Yes
Users are notified of available security updates, receive clear information after updates, and automatic security updates are enabled by default with an opt-out and recommended alternative mechanism where applicable
Yes
Users can securely and permanently remove their data and settings and, where applicable, transfer them to another product
Yes
Vulnerabilities and components are identified and documented, including an appropriate software bill of materials record
Yes
Vulnerabilities are addressed and remediated without delay, including through security updates where appropriate
Yes
Regular effective tests and reviews support product security and vulnerability handling
Yes
Information about fixed vulnerabilities, including description, identification, severity and impact where applicable, is published without undermining legitimate security interests
Yes
A coordinated vulnerability-disclosure policy is enforced and measures facilitate reporting and sharing information about vulnerabilities in the product and its third-party components, including a contact address
Yes
Security updates are distributed securely and without delay, free of charge unless the tailor-made business-product exception applies, with accessible advice about the fixed issue and user action
Yes
Technical documentation, EU declaration, support information and Annex II user information are assembled
Yes
An accountable product owner reviewed the completeness of this readiness record
No

Evaluated on 2026-09-13 using EU Cyber Resilience Act essential cybersecurity requirements readiness checklist, version 2026.09.02. A completed example is not a customer Record or a declaration of conformity.

Evidence to keep

  • Signed-release and distribution process
  • Update behaviour tests and user instructions
  • Applicable delivery terms and owner approval

Keep source artifacts in their controlled systems and record their references, responsible owner and review date with the decision.

Your next step

Test the release-to-user path and close the recorded delivery gap. Keep actual SBOMs and technical files in their managed systems and reference them from the assessment.

Choose your real product or vulnerability case in the workspace. The selected assessment will be highlighted; example answers are not copied into your record.

Sources and application dates

Manufacturer reporting applies from 11 September 2026. Broader product requirements apply from 11 December 2027; these product-readiness examples support preparation. Open-source-steward obligations have their own application date.

These examples structure a decision and do not replace the Regulation, official guidance or product-specific professional advice. Not lawyer-reviewed.

Related situations