CRA compliance matrix
Snapshot 6 October 2026. Status is only what evidence supports. Nothing is marked complete without git or published-docs evidence. Owners and dates: TBD.
Status key: Gap / Partial / Needs input.
Living Notion copy: Cyber Resilience Act (CRA). Overview: CRA.
| Requirement | Status | Evidence | Action |
|---|---|---|---|
| Scope / class (Art. 2, 7; Annex III; IR 2025/2392) | Needs input (working: default / Module A) | Working assumption 18 Sep 2026; adopted Annex III is a closed list | Legal confirm core functionality vs VPN / NMS / SIEM / OS / container runtime |
| Art. 14 SRP reporting (since 11 Sep 2026) | Partial | Reporting explains AR / EU Login / CSIRT / SRP; person and CSIRT row still TBD | Name Primary AR; confirm legal entity / main establishment; EU Login + MFA |
| Art. 14(8) inform users | Partial | Procedure: email impacted operators + security advisories + GHSA + monitored info@roasthubs.com | Name on-call CRA reporter; keep GHSA index current |
| Annex I Part I §1 risk-based cybersecurity | Gap | Notion risk-assessment draft | Complete and sign |
| §2 no known exploitable vulnerabilities | Partial | Pentests June 2026 (Notion); Renovate; partial ECR scan | Close findings; scan all product images |
| §3 secure by default | Partial | session.ts requires SESSION_SECRET; prod secret set per host and monitored; compose still publishes ports | Default-deny ports |
| §4 unauthorised access | Partial | Auth/RBAC, SSH keys, Cloudflare tunnel | Harden OT/OPC UA; close unused ports |
| §5 confidentiality | Partial | TLS nginx + tunnel; LUKS | Document data classes and encryption at rest |
| §6 integrity | Partial | Digest compare + Cosign verify in deploy.sh; Activity Feed | Recipe/config integrity; cut over first signed image |
| §7 data minimisation | Needs input | — | Document categories and retention |
| §8 essential functions | Partial | SLA themes (Notion); network requirements | Define roasting fail-safe / offline behaviour |
| §9 impact on other devices | Needs input | Network requirements | Isolation / rate limits |
| §10 attack surface | Gap | Compose publishes 5432/9090/9100/3001; ZeroTier :9993 being replaced by Cloudflare overlay (site inventory still in progress) | Inventory listeners; bind to localhost; finish overlay migration |
| §11 incident impact | Partial | Incident policy (Notion); LUKS; RBAC | Backup/restore runbooks |
| §12 security logging | Partial | winston, CloudWatch, auth logs | Event catalogue, retention, review |
| §13 data removal | Partial | rhsos-infra/docs/factory-reset-and-decommission.md (draft) | Validate; publish customer steps |
| Part II §1 SBOM | Partial | SBOM for v0.0.0.3; retained on GitHub Releases; CI Trivy continue-on-error | Pin compose images; decide when the scan gate blocks release |
| Part II §2 remediate without delay | Partial | Renovate; deploy script | Severity SLAs; security-only track |
| Part II §3 tests | Partial | Pentests June 2026 | Recurring cadence |
| Part II §4 public disclosure of fixes | Partial | Process: GHSA + security advisories; none published yet | Publish a row when the first GHSA goes out |
| Part II §§5–6 CVD / intake | Partial | Vulnerability disclosure — info@roasthubs.com, monitored; phone still TODO | Add phone if required for public CRA contact |
| Part II §7 secure updates | Partial | Secure updates: Cosign sign on ECR push, verify at deploy | Pin compose digests; cut over first signed image |
| Part II §8 free timely security updates + support period | Gap | Support period is draft | Legal/commercial Annex II statement |
| Art. 13 tech docs / DoC / CE | Gap / Partial | This pack + git; no DoC/CE | Assemble file before 11 Dec 2027 |
| Art. 19 authorised representative | Needs input | — | Confirm Union establishment |
| Annex II manufacturer identity / product ID | Needs input | — | Legal entity + stable name/version |
| Annex II intended purpose / secure environment | Partial | Network requirements (ZeroTier being replaced) | User-facing install environment |
| Annex II how to apply updates | Partial | Secure updates; security advisories | Keep operator instructions aligned with signed deploys |