Skip to main content

Cyber Resilience Act (CRA)

This Compliance section collects Roasthubs CRA requirements, compliance status, and linked evidence for the edge product placed on the EU market: Welotec IPC + Docker Compose (rhsos-infra) + roasthubs-os + collectors, used by coffee roasteries.

Last evidence refresh: 6 October 2026. Status is only what git and published docs support. Owners and dates are TBD. This is manufacturer documentation, not a signed EU declaration of conformity.

The operational living matrix also lives in Notion (Cyber Resilience Act (CRA)). This docs pack is the public collection of the same requirements and evidence.

Pack on this site​

TopicPage
Obligations, timelines, classification, to-doThis page
Requirement → status → evidence → actionCompliance matrix
Art. 14 reporting (live since 11 Sep 2026)Incident and vulnerability reporting
Annex II support period (draft)Support period
How edge software is updated (draft)Secure updates
Coordinated vulnerability disclosureVulnerability disclosure
Public security advisoriesSecurity advisories
Machine-readable SBOMSoftware bill of materials
Install / network environmentNetwork requirements

Use the docs version dropdown for a frozen copy of an older roasthubs-os release. The default is the latest product tag.

Product and working classification​

Product: SME placing an edge stack on the EU market (hardware + software + remote update/support path).

Working classification (not a signed legal opinion): default product, Module A self-assessment, not Annex III important unless core marketed functionality matches a listed category. Confirm against Implementing Regulation (EU) 2025/2392 (core functionality, Art. 7(1) and 8(1)). Adopted Annex III does not list IACS/SCADA (that was draft CRA text). Nearby listed categories for counsel: VPN, network management, SIEM, operating system as the product placed, Class II container runtime. Supporting Cloudflare or ZeroTier remote access, or Docker as a runtime, does not automatically change class.

Legal entity, product name/version, Union establishment, and support-period commercial terms are TBD. Do not treat placeholders as customer-binding.

What applies when​

WhenWhat
Since 11 Jun 2026Chapter IV — notification of conformity assessment bodies (Art. 71).
Since 11 Sep 2026Art. 14 reporting of actively exploited vulnerabilities and severe incidents via the ENISA Single Reporting Platform. Applies to in-scope products already on the market.
From 11 Dec 2027Annex I essential cybersecurity requirements, Art. 13 manufacturer duties (including risk assessment, support period, technical documentation, EU DoC, CE marking), Annex II information for users.

Primary sources: Regulation (EU) 2024/2847, IR 2025/2392, Delegated Regulation (EU) 2026/881 (CSIRT dissemination delay only), Commission CRA reporting and C(2026) 5252 guidance (non-binding), ENISA SRP.

Prioritized to-do (owners TBD)​

P0 — Art. 14 is already live

  1. Name Primary Assigned Representative and on-call CRA reporter (TBD). What this is, how EU Login + MFA and CSIRT selection work: reporting. Portal: portal.cra-srp.enisa.europa.eu.
  2. Member States where the product is made available: all EU-27 (list on reporting).
  3. How users are informed (Art. 14(8)): security advisories + email to impacted operators (reporting).
  4. info@roasthubs.com is the published CVD address and is monitored.
  5. Production SESSION_SECRET is set per placed host and monitored. Compose ports 5432 / 9090 / 9100 / 3001 remain published.

P0 — attack surface

  1. Stop publishing compose ports 5432 / 9090 / 9100 / 3001; inventory live listeners.
  2. ZeroTier UDP/TCP 9993 is being replaced by the Cloudflare overlay. New installs: Cloudflare only (UDP 443 / 7844). Keep 9993 only until a site is migrated. Per-site live inventory still in progress.

P1 — vulnerability handling and 11 Dec 2027 pack

  1. SBOMs for placed versions are retained on GitHub Releases. Still open: pin compose images; decide when the Trivy scan gate blocks release.
  2. Cosign keyless signing of ECR images + verify at deploy, and a public advisories process, are in git. First signed image still has to land on hosts (ALLOW_UNSIGNED_IMAGE=1 only for that cutover).
  3. Sign the cyber risk assessment; legal class confirmation; Annex II support-period statement; tech file → DoC → CE.

Full rows: compliance matrix.