Loading...
 
Skip to main content

Cyber Resilience Act compliance service by Open Source Solutions

CRA compliance for software vendors and distributors

If you sell a plugin, a module, an image or an appliance, you have 24 hours to report any actively exploited vulnerability. From 11 September 2026.

  • In force on 11 September 2026
  • Early warning within 24 h
  • Coordinated disclosure published
  • Covers the installed base
  • Am I in scope? Answer in 1 h
  • A written procedure
  • Pre-filled report templates
  • Software bill of materials (SBOM)
  • CVE watch and KEV catalogue
  • Response within 8 h
  • Written, dated audit trail
  • Web software scope, stated up front
The Cyber Resilience Act is not just for connected device makers. It applies to anyone placing a digital product on the European market under their own name, in the course of a commercial activity. A theme you sell, a module you distribute, a Docker image under your brand, a fork you maintain: you are a manufacturer, with the obligations that come with it. Most of the people this covers still don't know it.

From 11 September 2026, an actively exploited vulnerability in one of your products has to be reported within 24 hours, including on a product shipped five years ago and still running at a customer site. Penalties reach 15 million euros or 2.5% of worldwide annual turnover. Nobody expects that ceiling to be used against a small company, but the obligation itself does not scale with your size. We give you a way to know where you stand, what you need to publish, and who decides on the day it happens. To understand the framework first, read our article The Cyber Resilience Act's first deadline hits in September.

What the regulation actually requires

Three obligations take effect on 11 September. Report within 24 hours any actively exploited vulnerability or severe incident, then file a full notification within 72 hours, then a final report. Publish a coordinated disclosure policy: a security contact address that genuinely exists, a security.txt file, a page setting out how you receive a report. Handle vulnerabilities in a documented way, and inform your users.

The design requirements, software bill of materials, CE marking, no known exploitable vulnerability at the time of placing on the market, arrive in December 2027. They are not retroactive. The reporting obligation, on the other hand, covers everything you have already shipped.

What we do, and what we don't

We work on the web software stack: CMSs, extensions, modules, images and appliances, PHP applications and Linux servers. It is what we run every day and have done for twenty years, and it is where our opinion is worth something.

We don't take on embedded firmware, hardware, or medical devices. Tracing a firmware subcontracting chain calls for skills we don't have, and a sloppy bill of materials in that field would put you at risk rather than in compliance. If your product is hardware, we say so on the first call and point you elsewhere.

Three steps: find out, get compliant, stay there

The first question is not "how do I become compliant" but "does this apply to me". Many who think it does are wrong: a hosting provider, an integrator, a company running a CMS for its own business are not manufacturers. The reverse is true too, someone who has been selling a module for years does not picture themselves as a digital product manufacturer. So we settle that first, then build what is needed, then keep it running.

CRA scope assessment

Free until 11 September
One hour of discussion - Written document
  • Manufacturer, distributor, steward or out of scope
  • The exact criteria, not just the verdict
  • The obligations that follow for you
  • What is due in 2026, and what in 2027
  • No strings attached
Find out if this applies to me

Reporting procedure

€1,500
Delivered within 5 working days
  • Coordinated disclosure policy published
  • security@ address and security.txt file in place
  • Decision matrix: who, when, on what grounds
  • Report templates (24/72 h and 14 days)
  • A simple protocol your team can actually follow
Be ready for the 11th

Monitoring and response

€200 / month
3 software packages monitored, €50 per additional package
  • CVE watch on each package and its dependencies
  • KEV catalogue and national CSIRT advisories
  • Response within 8 hours, weekends included
  • Assessment of active exploitation
  • Help drafting the report
Set up monitoring
Software bill of materials (SBOM): €800 - an inventory of your dependencies in CycloneDX or SPDX format, for a software project. Not required before December 2027, but without it monitoring is blind: it is the prerequisite for the subscription above. Web software scope only. Embedded firmware and hardware are outside our expertise; we will point you elsewhere.

What "response within 8 hours" means, and what it doesn't

We would rather put this in writing than discover it together on a Sunday morning. The response is not the fix. Within 8 hours we get back to you, we establish whether the flaw is genuinely being exploited, we work out which products and which deployments are affected, and we help you draft the report. Fixing the code is separate work, quoted on its own or covered by your maintenance contract.
The clock starts when we detect it or when you call, not when the flaw was first exploited in the wild. And we never file on your behalf: the obligation sits with the manufacturer and cannot be delegated. We prepare, you sign. Finally, monitoring covers a list of packages named in the contract. What is not on the list is not watched, and we would rather hold a short list than make a broad, empty promise.

A package is one thing you distribute: a plugin, a theme, an image, an appliance. Different versions of the same package count as one.

The stack that makes compliance sustainable

CRA compliance is not a document to produce, it is an operational capability. Reporting a flaw within 24 hours means knowing it is being exploited, which means having logs and monitoring that show it. Proving you did what was needed means a written trail. Recovering after an incident means tested backups. We already run these building blocks for our clients, and they plug straight into your compliance setup.

Every month, depending on your service level, we document the alerts handled, the fixes applied and the decisions taken. The day an authority, an insurer or a client asks what you did, the answer is in writing and dated.

Continuous monitoring
Without logs and monitoring you will not know a flaw is being actively exploited, and that is precisely what starts the 24-hour clock. Read more

Offsite backup
Encrypted backup on private infrastructure in France, with documented restore testing. Continuity is part of the compliance file. Read more

Maintenance and patching
Reporting a flaw is not enough, it has to be fixed. Our maintenance plans apply patches as soon as they ship, across your whole stack. Read more

Frequently Asked Questions

Absolutely. Security is not just about code; it is about compliance. We integrate Privacy by Design principles using tools like Matomo for sovereign and GDPR-compliant analytics. We support our clients on the Cyber Resilience Act requirements, which apply from September 2026 for vulnerability reporting.

Two dates, not one. On 11 September 2026 the reporting obligation becomes enforceable: 24 hours for an early warning, 72 hours for the full notification, 14 days for the final report. It covers everything you have already shipped. On 11 December 2027 the design requirements follow: software bill of materials, CE marking, no known exploitable vulnerabilities at the time of placing on the market. Those apply only to products placed on the market after that date.

Failure to meet the reporting obligation carries penalties of up to 15 million euros or 2.5% of worldwide annual turnover. That ceiling is aimed at serious failures, not at a small business that filed two hours late. For a small company the real exposure lies elsewhere: a client demanding proof of compliance before signing, an insurer taking an interest after an incident, a competitor publishing a disclosure policy when you have none.

Not under the CRA. The regulation targets those who place a digital product on the market, not those who use one. Running Tiki, WordPress or Nextcloud for your own business does not make you a manufacturer. Neither your hosting provider nor your integrator is one either: they supply a service.

It still reaches you indirectly, through your suppliers. From September 2026 they have to declare their exploited flaws, which makes their diligence verifiable and therefore contractual. Four questions worth asking them now: how quickly do they inform you, what support period do they state, have they published a reporting channel, and do they supply a software bill of materials. A supplier who cannot answer in 2026 will cost you dearly in 2027.

The 24-hour deadline runs in calendar hours. It does not pause for weekends or for August. A flaw confirmed under exploitation at 8 p.m. on a Friday has to be reported before 8 p.m. on the Saturday.

That is exactly what our monitoring subscription covers. Within 8 hours we get back to you, we establish whether the flaw is genuinely being exploited, a published proof of concept is not enough to start the clock, we work out which software and which deployments are affected, and we help you draft the report. A package is one thing you distribute: a plugin, a theme, an image, an appliance. Different versions of the same package count as one.

Limits we prefer to put in writing: the response is not the fix, which falls under your maintenance contract; and we never file on your behalf, because the obligation sits with the manufacturer and cannot be delegated.

Because the value is not in the page count, it is in the decisions those pages settle. A reporting procedure worth having answers precise questions: what evidence counts as active exploitation, who is allowed to file, what happens when that person is unreachable, which information has to be at hand before the form is opened. Those calls take knowledge of both the regulation and your organisation.

Set it against the alternative: improvising on a Sunday morning with a 24-hour clock running, or finding out afterwards that the wrong thing was filed. The fee covers the document, the technical work around it, contact address, security.txt file, published disclosure page, and a walkthrough with your team. We quote five working days and a fixed price, not an open-ended engagement.

Because we don't write compliance in the abstract; we run the stack your risk actually sits on. Twenty years of CMSs, extensions, Linux servers and monitoring, with a CVE watch already running for our clients. When a flaw lands on a component you use, we know what it does, not just which article of the regulation it triggers. And you get one person who knows your setup and who you reach directly.

We also say no. Embedded firmware, hardware and medical devices are outside our expertise, and we tell you so on the first call rather than billing for work we would do badly. If your need goes beyond our scope, a specialist consultancy is the right answer and we will say so.

Further reading

One hour is enough to know which side you are on

Nobody should discover their regulatory status on the day the flaw gets exploited. Tell us what you sell, and we will tell you whether the CRA applies to you, and what is left to do before 11 September.

Request my assessment