CRA Compliance Kit – EU Cyber Resilience Act in One Pip Install
a day ago
- The EU Cyber Resilience Act (CRA) mandates reporting actively exploited vulnerabilities within 24 hours, with penalties up to €15 million or 2.5% of global turnover.
- The CRA Compliance Kit is a Python package (pip install cra-compliance-kit) that provides 9 modules covering device identity, firmware CVE matching, input sanitization, SBOM generation, and more, with zero external dependencies.
- A Software Bill of Materials (SBOM) in CycloneDX or SPDX format is required under CRA Article 13 to trace vulnerabilities to components; the kit automatically monitors the CISA KEV catalog and matches against your SBOM.
- CRA Article 14 defines a three-stage reporting timeline: 24-hour ENISA notification, 72-hour status update, and 14-day final report. VEX statements provide auditable due diligence evidence.