CRA · READINESS · v1

The Cyber Resilience Act puts cybersecurity obligations on the product, not just the operator.

From 11 December 2027, every product with digital elements placed on the EU market needs CE marking against the EU Cyber Resilience Act — Regulation 2024/2847. CodeB Sovereign Communications is being engineered to be ready: secure-by-design, vulnerability-handling pipeline already published, SBOM available on request, support period declared. Below: what the CRA actually requires, where CodeB stands today, and what’s left between now and the deadline.

Important legal note. CodeB is not CRA-certified today — CRA certification cannot be granted yet because the regulation’s substantive obligations apply from 11 December 2027 and the harmonised-standard + notified-body infrastructure is still ramping. The right phrasing is “CRA-aligned posture” or “engineered for the December 2027 obligations”. Anyone claiming CRA certification today is either confused or being dishonest.
01 / What the CRA is

Horizontal cybersecurity law for digital products.

The EU Cyber Resilience Act — Regulation (EU) 2024/2847 — was adopted in October 2024 and came into force on 11 December 2024. It is the EU’s first horizontal cybersecurity rulebook for “products with digital elements” (PDEs): hardware and software with direct or indirect data connections to a device or network. It does for software what the General Product Safety Regulation does for kettles — mandatory CE marking, conformity assessment proportional to risk, and lifecycle-long manufacturer responsibility.

Key obligations on a manufacturer:

Penalties go up to €15M or 2.5% of worldwide turnover, whichever is higher. So this has teeth.

02 / The dates that matter

Two deadlines, not one.

The CRA staggers its obligations — you can’t treat it as a single “December 2027” cliff.

Practical implication for a buyer doing procurement now: vendors who don’t have at least a published security.txt and a written CVD policy by autumn 2026 are already behind. CodeB has both today.
03 / CodeB’s classification

Important Class I, in our reading.

The CRA splits products into four risk bands: default, Important Class I, Important Class II, and Critical. Higher bands need more independent assessment. Our reading of Annex III places CodeB in Important Class I because the platform includes identity-management functionality (the built-in OpenID Connect provider and the EU Wallet verifier) and is a network-management tool. That means:

This is our reading — final classification depends on the harmonised standards and Commission guidance still being published. We monitor the ENISA and Commission output continuously and will republish this page when the formal classification is settled.
04 / Where CodeB stands today

What’s already in place, and what’s on the workplan.

ALIGNED TODAY

Coordinated vulnerability disclosure

Published per RFC 9116 at /.well-known/security.txt on every deployment. PGP-signed reports accepted; 90-day default disclosure window; credit on request.

ALIGNED TODAY

Secure by default

DTLS-SRTP on all WebRTC media, OIDC-only auth with PKCE mandatory, per-tenant cryptographic keys, no third-party media path, no analytics SDKs, ephemeral keys per presentation.

ALIGNED TODAY

Audit logging

Per-tenant security-event log with the structured trail required for incident reconstruction. Three audit channels for password lifecycle events. Webhook dispatcher emits signed call-lifecycle events.

ALIGNED TODAY

No mandatory third-party cloud

Self-hosted on customer Windows + IIS. Optional AI Voice Engine backend is per-tenant configurable; on-premise backend supported for air-gap deployments.

WORKPLAN

SBOM publication

Component list is tracked implicitly in the project references. Formal CycloneDX-format SBOM with hashes is on the 2026 workplan, available on request before that.

WORKPLAN

Conformity assessment

Third-party assessment against EN 18031 (or the successor harmonised standard) is scheduled for 2026/early 2027 ahead of the December 2027 deadline. Notified body selection in progress.

WORKPLAN

Support-period declaration

Formal written declaration of the support period (minimum five years from last shipment) attached to the product documentation. Drafted; final version with the 2027 release.

WORKPLAN

Incident-reporting playbook

24h ENISA / national-CSIRT early-warning workflow formalised in writing, with named responsibilities. Already practised informally; written playbook attached to the 2026 CVD policy revision.

05 / Regulatory neighbours

The CRA does not stand alone.

Four EU regulations interact with CodeB’s posture. Buyers in regulated sectors usually need to satisfy several at once.

NIS2 — Directive (EU) 2022/2555

Regulates operators of essential / important entities across 18 sectors. Enforcement live since 2025. NIS2-covered entities buying a non-CRA-compliant product after December 2027 face a compliance gap on both sides. CodeB’s self-hosted posture and audit logging materially simplify NIS2 evidence-gathering.

DORA — Regulation (EU) 2022/2554

Applies to financial entities since 17 January 2025. ICT-third-party-risk obligations directly map to vendor questionnaires. CodeB’s data-residency-on-your-server posture removes most ICT-third-party-risk questions before they need to be answered.

EU AI Act — Regulation (EU) 2024/1689

Transparency obligations from 2 August 2026 require AI interactions to be disclosed to the user. CodeB Voice AI’s persona prompts already disclose “you are speaking to an AI” in the first sentence; see the AI-call privacy page.

eIDAS 2.0 — Regulation (EU) 2024/1183

EU Digital Identity Wallet acceptance becomes mandatory for private-sector strong-customer-authentication services from December 2027 — same date as the CRA cliff. CodeB’s EU Wallet verifier is shipped today; see the proof page.

06 / For procurement and security teams

What to ask any communications vendor right now.

If you’re evaluating a communications platform in 2026 for a deployment that has to be alive after December 2027, here’s the short questionnaire:

CodeB’s answers to all of the above are documented and available on request. Contact us for the current versions.

07 / Where to next

Related reading.