Skip to main content
Version: Next

CRA compliance matrix

Snapshot 6 October 2026. Status is only what evidence supports. Nothing is marked complete without git or published-docs evidence. Owners and dates: TBD.

Status key: Gap / Partial / Needs input.

Living Notion copy: Cyber Resilience Act (CRA). Overview: CRA.

RequirementStatusEvidenceAction
Scope / class (Art. 2, 7; Annex III; IR 2025/2392)Needs input (working: default / Module A)Working assumption 18 Sep 2026; adopted Annex III is a closed listLegal confirm core functionality vs VPN / NMS / SIEM / OS / container runtime
Art. 14 SRP reporting (since 11 Sep 2026)PartialReporting explains AR / EU Login / CSIRT / SRP; person and CSIRT row still TBDName Primary AR; confirm legal entity / main establishment; EU Login + MFA
Art. 14(8) inform usersPartialProcedure: email impacted operators + security advisories + GHSA + monitored info@roasthubs.comName on-call CRA reporter; keep GHSA index current
Annex I Part I §1 risk-based cybersecurityGapNotion risk-assessment draftComplete and sign
§2 no known exploitable vulnerabilitiesPartialPentests June 2026 (Notion); Renovate; partial ECR scanClose findings; scan all product images
§3 secure by defaultPartialsession.ts requires SESSION_SECRET; prod secret set per host and monitored; compose still publishes portsDefault-deny ports
§4 unauthorised accessPartialAuth/RBAC, SSH keys, Cloudflare tunnelHarden OT/OPC UA; close unused ports
§5 confidentialityPartialTLS nginx + tunnel; LUKSDocument data classes and encryption at rest
§6 integrityPartialDigest compare + Cosign verify in deploy.sh; Activity FeedRecipe/config integrity; cut over first signed image
§7 data minimisationNeeds input—Document categories and retention
§8 essential functionsPartialSLA themes (Notion); network requirementsDefine roasting fail-safe / offline behaviour
§9 impact on other devicesNeeds inputNetwork requirementsIsolation / rate limits
§10 attack surfaceGapCompose publishes 5432/9090/9100/3001; ZeroTier :9993 being replaced by Cloudflare overlay (site inventory still in progress)Inventory listeners; bind to localhost; finish overlay migration
§11 incident impactPartialIncident policy (Notion); LUKS; RBACBackup/restore runbooks
§12 security loggingPartialwinston, CloudWatch, auth logsEvent catalogue, retention, review
§13 data removalPartialrhsos-infra/docs/factory-reset-and-decommission.md (draft)Validate; publish customer steps
Part II §1 SBOMPartialSBOM for v0.0.0.3; retained on GitHub Releases; CI Trivy continue-on-errorPin compose images; decide when the scan gate blocks release
Part II §2 remediate without delayPartialRenovate; deploy scriptSeverity SLAs; security-only track
Part II §3 testsPartialPentests June 2026Recurring cadence
Part II §4 public disclosure of fixesPartialProcess: GHSA + security advisories; none published yetPublish a row when the first GHSA goes out
Part II §§5–6 CVD / intakePartialVulnerability disclosure — info@roasthubs.com, monitored; phone still TODOAdd phone if required for public CRA contact
Part II §7 secure updatesPartialSecure updates: Cosign sign on ECR push, verify at deployPin compose digests; cut over first signed image
Part II §8 free timely security updates + support periodGapSupport period is draftLegal/commercial Annex II statement
Art. 13 tech docs / DoC / CEGap / PartialThis pack + git; no DoC/CEAssemble file before 11 Dec 2027
Art. 19 authorised representativeNeeds input—Confirm Union establishment
Annex II manufacturer identity / product IDNeeds input—Legal entity + stable name/version
Annex II intended purpose / secure environmentPartialNetwork requirements (ZeroTier being replaced)User-facing install environment
Annex II how to apply updatesPartialSecure updates; security advisoriesKeep operator instructions aligned with signed deploys