Skip to main content

Cyber Resilience Act Compliance: A Practical Guide for SMEs — and How OSCRAT Can Help

A practical CRA compliance guide for European SMEs: check if the Cyber Resilience Act applies to your product, then manage SBOMs, vulnerabilities, incidents, risk and documentation with OSCRAT — the free, open-source CRA platform.

Predrag Tasevski September 25, 2026 8 min read
OSCRAT Cyber Resilience Act CRA Compliance Products with Digital Elements SME Security Open-Source Security Tools SBOM Vulnerability Management

The EU Cyber Resilience Act (CRA) is changing the cybersecurity requirements for every product with digital elements placed on the European market, from smart devices and industrial controllers to standalone software.

For most small and medium-sized enterprises, understanding the regulation is only part of the problem. The harder part is turning its requirements into cybersecurity processes, documentation and evidence that can be kept up to date for the whole product lifecycle.

That is the job OSCRAT was built for.

OSCRAT is a free, open-source platform that helps European SMEs understand, manage and meet the requirements of the Cyber Resilience Act. It is co-funded by the European Union and built on the Unicis open-source platform.

Free · 2-minute check

Does the Cyber Resilience Act apply to your product?

Answer a few questions and find out whether your product falls within the CRA's scope before you spend anything on compliance.

Check CRA applicability →

Key takeaways

  • Start with scope. Before building a compliance programme, confirm whether the CRA applies to your product. OSCRAT’s free CRA Applicability Check is the place to start.
  • Compliance means evidence. Policies on paper are not enough. You need SBOMs, vulnerability handling, incident processes and documentation you can show to an auditor.
  • One platform, end to end. OSCRAT brings SBOMs, vulnerabilities, risk, incidents, actions, documentation and self-assessment together in one place.
  • Free and open source. No licence fees. SMEs can try it without first committing to an expensive commercial compliance tool.
  • The clock is running. CRA vulnerability and incident reporting obligations apply from 11 September 2026, and the full set of requirements applies from 11 December 2027.

Step one: does the CRA apply to your product?

Before starting a compliance programme, you need to know whether your products fall within the scope of the CRA.

This matters most for companies that develop or manufacture products with digital elements, including products that combine hardware and software or depend on digital functionality. Importers and distributors have obligations too.

OSCRAT’s CRA Applicability Check is built for this first step. The project’s training materials name scope, affected products and responsibilities across the supply chain as some of the first operational questions SMEs have to answer.

Not sure where you stand? Run the free CRA Applicability Check →

If the CRA does apply to your product, the next question is:

How do you actually manage the compliance work?

That is where the OSCRAT platform comes in.


From regulatory requirements to practical compliance

CRA compliance is more than a set of cybersecurity policies.

You need to understand your risks, find and manage vulnerabilities, keep product information current, handle incidents, and produce the documentation and evidence that shows you comply.

OSCRAT brings these activities together in one open-source platform:

📦 SBOM generation and management

Know exactly what is inside your product. OSCRAT supports SBOM generation and management so you can track the software components in your products and feed that information into your security processes. It supports SBOM manifests and standard formats including SPDX and CycloneDX.

🔍 Vulnerability assessment

Find weaknesses before attackers do. OSCRAT uses publicly available security information and OVAL streams covering operating systems, where available, to help SMEs identify and continuously evaluate vulnerabilities.

🚨 Incident response

Be ready when something goes wrong. The platform includes incident-management capabilities that help SMEs manage cybersecurity incidents and support the relevant reporting processes. Its documentation follows guidance from the OpenSSF OSS-SIRT Special Interest Group on incident management and reporting to the relevant European cybersecurity organisations. (See also: Unicis Incident Management.)

⚖️ Risk and action management

Finding a vulnerability is only the beginning. You also need to decide what to do about it, who is responsible, and whether the fix is done.

OSCRAT supports the continuous identification and evaluation of vulnerabilities, corrective measures, and compliance and risk treatment actions, so nothing falls through the cracks. (See also: Unicis Risk Management.)

🗂️ Centralised documentation

CRA compliance produces a lot of documentation. OSCRAT gives you one repository for your digital product documentation, including:

  • Conformity assessment reports
  • SBOM reports
  • Vulnerability disclosure policies
  • Incident reports
  • Certificates of conformity

✅ Self-assessment and audit support

Compliance has to be backed by evidence, not by statements that security measures exist. OSCRAT supports self-assessment and the collection of evidence you can hand to auditors. The project’s training materials stress that structured evidence and conformity assessment are what make compliance credible.

All of your CRA work in one open-source platform

SBOMs, vulnerabilities, risk, incidents, actions, documentation and self-assessment, with no licence fees.


Why an open-source platform?

Cybersecurity compliance can put real pressure on an SME’s resources. Specialist consultants, commercial compliance platforms and security tools all add cost and complexity.

OSCRAT takes a different approach:

  • 💶 Free to use. No licence fees and no financial or licensing barriers to testing and rolling out the tools.
  • 🔓 Open and adaptable. You can inspect it, adapt it and fit it to how your organisation already works.
  • 🌍 Community-driven. The open-source model means the platform can keep evolving with the community after the EU-funded project ends.
  • 🇪🇺 Built in Europe, for Europe. Developed by a consortium of European SMEs and research institutes, including Unicis, PMF Research, OVES Enterprise, Enersec, EDIH Trakia and EMAG. Meet the consortium →

For an SME, this means you can explore the platform and build real compliance processes before paying for an expensive commercial solution.


Don’t leave CRA compliance to the last minute

Start early. That is one of the most important parts of CRA preparation.

Your cybersecurity processes, vulnerability management, product documentation and evidence should not be pulled together at the very end of the compliance process. Reporting obligations for actively exploited vulnerabilities and severe incidents already apply from 11 September 2026, so the work needs to be running now.

OSCRAT is built for this: risk assessment, vulnerability management, incident handling, documentation and compliance actions are managed as one ongoing process, not a one-off project.

The project’s training programme also takes organisations from understanding the CRA to implementing it, covering:

  1. Scope and accountability
  2. Standards and conformity assessment
  3. Gap analysis
  4. Readiness for conformity assessment

Want the background first? Read our earlier explainer: Is Your Organization Affected by the Cyber Resilience Act?


Ready to take the first step?

If you manufacture or develop a product with digital elements, here is your path to CRA readiness:

Step 1: Check CRA applicability

Use the free OSCRAT CRA Applicability Check to find out whether the CRA applies to your product.

👉 Check if the CRA applies to your product

Step 2: Create your free OSCRAT account

If the CRA applies, continue your compliance work with OSCRAT.

👉 Create your free OSCRAT account

Step 3: Start managing your compliance activities

Use the OSCRAT platform to work through each area:

SBOMs → Vulnerabilities → Risk → Incidents → Actions → Documentation → Assessment

All in an open-source platform designed for SMEs.

Get CRA-ready without the enterprise price tag

Join the European SMEs using OSCRAT to turn Cyber Resilience Act requirements into processes, documentation and evidence they can manage.

Need help with CRA, ISO 27001 or NIS2 beyond the product level? Talk to the Unicis team.

OSCRAT (Open-Source Cyber Resilience Act Tools) is co-funded by the European Union. Learn more at oscrat.eu.

Unicis Platform

Ready to automate your GRC workflow?

Join teams using Unicis to manage privacy compliance, cybersecurity controls, and regulatory frameworks — all in one open-source platform.