Cyber Resilience Act (CRA)
This Shared section collects Roasthubs CRA requirements, compliance status, and linked evidence for the edge product placed on the EU market: Welotec IPC + Docker Compose (rhsos-infra) + roasthubs-os + collectors, used by coffee roasteries.
Last evidence refresh: 6 October 2026. Status is only what git and published docs support. Owners and dates are TBD. This is manufacturer documentation, not a signed EU declaration of conformity.
The operational living matrix also lives in Notion (Cyber Resilience Act (CRA)). This docs pack is the public collection of the same requirements and evidence.
Pack on this site
| Topic | Page |
|---|---|
| Obligations, timelines, classification, to-do | This page |
| Requirement → status → evidence → action | Compliance matrix |
| Art. 14 reporting (live since 11 Sep 2026) | Incident and vulnerability reporting |
| Annex II support period (draft) | Support period |
| How edge software is updated (draft) | Secure updates |
| Coordinated vulnerability disclosure | Vulnerability disclosure |
| Public security advisories | Security advisories |
| Machine-readable SBOM | Software bill of materials |
| Install / network environment | Network requirements |
Use the docs version dropdown for a frozen copy after a release cut. Next is the working tree.
Product and working classification
Product: SME placing an edge stack on the EU market (hardware + software + remote update/support path).
Working classification (not a signed legal opinion): default product, Module A self-assessment, not Annex III important unless core marketed functionality matches a listed category. Confirm against Implementing Regulation (EU) 2025/2392 (core functionality, Art. 7(1) and 8(1)). Adopted Annex III does not list IACS/SCADA (that was draft CRA text). Nearby listed categories for counsel: VPN, network management, SIEM, operating system as the product placed, Class II container runtime. Supporting Cloudflare or ZeroTier remote access, or Docker as a runtime, does not automatically change class.
Legal entity, product name/version, Union establishment, and support-period commercial terms are TBD. Do not treat placeholders as customer-binding.
What applies when
| When | What |
|---|---|
| Since 11 Jun 2026 | Chapter IV — notification of conformity assessment bodies (Art. 71). |
| Since 11 Sep 2026 | Art. 14 reporting of actively exploited vulnerabilities and severe incidents via the ENISA Single Reporting Platform. Applies to in-scope products already on the market. |
| From 11 Dec 2027 | Annex I essential cybersecurity requirements, Art. 13 manufacturer duties (including risk assessment, support period, technical documentation, EU DoC, CE marking), Annex II information for users. |
Primary sources: Regulation (EU) 2024/2847, IR 2025/2392, Delegated Regulation (EU) 2026/881 (CSIRT dissemination delay only), Commission CRA reporting and C(2026) 5252 guidance (non-binding), ENISA SRP.
Prioritized to-do (owners TBD)
P0 — Art. 14 is already live
- Name Primary Assigned Representative and on-call CRA reporter (TBD). What this is, how EU Login + MFA and CSIRT selection work: reporting. Portal: portal.cra-srp.enisa.europa.eu.
- Member States where the product is made available: all EU-27 (list on reporting).
- How users are informed (Art. 14(8)): security advisories + email to impacted operators (reporting).
- info@roasthubs.com is the published CVD address and is monitored.
- Production
SESSION_SECRETis set per placed host and monitored. Compose ports 5432 / 9090 / 9100 / 3001 remain published.
P0 — attack surface
- Stop publishing compose ports 5432 / 9090 / 9100 / 3001; inventory live listeners.
- ZeroTier UDP/TCP 9993 is being replaced by the Cloudflare overlay. New installs: Cloudflare only (UDP 443 / 7844). Keep 9993 only until a site is migrated. Per-site live inventory still in progress.
P1 — vulnerability handling and 11 Dec 2027 pack
- SBOMs for placed versions are retained on GitHub Releases. Still open: pin compose images; decide when the Trivy scan gate blocks release.
- Cosign keyless signing of ECR images + verify at deploy, and a public advisories process, are in git. First signed image still has to land on hosts (
ALLOW_UNSIGNED_IMAGE=1only for that cutover). - Sign the cyber risk assessment; legal class confirmation; Annex II support-period statement; tech file → DoC → CE.
Full rows: compliance matrix.