ciso.diy
Product Security Complete preview
Bundles Cyber Resilience ActCRACE markingSBOM

Product Security Complete

Everything a product vendor owes the EU and the crypto clock in one purchase — the CRA scope test, the Article 14 reporting runbook, the technical file with SBOM and CE declaration, and the post-quantum inventory and migration plan. 19% off buying the four separately.

What this actually gives you

  • A product you CE-mark in 2027 with a ten-year support commitment is one you have promised to keep cryptographically current into the 2030s — which is why the SBOM and the crypto inventory belong in the same purchase.
  • Article 14 reporting starts 11 September 2026; full CRA applies 11 December 2027; NIST deprecates RSA-2048 and P-256 after 2030.
  • Sold as a Standard licence because two of the four components are sold that way — buy the conformity or post-quantum kits directly if you need Organization or MSSP scope.

If you ship a product with digital elements into the EU, three deadlines are already moving and a fourth is arriving underneath all of them.

EU Cyber Resilience Act Workbook — whether the regulation attaches to you at all, the Annex I essential requirements mapped against controls you may already have, the conformity routes, and the dated road to December 2027.

CRA 24-Hour Reporting Clock — starting 11 September 2026, so the first part of this set that binds. The actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA drafts and a coordinated disclosure policy you publish under your own name.

CRA Conformity Package — for 11 December 2027: the product classifier, the Annex I checklist, the conformity route decision with notified-body lead times, the Annex VII technical documentation template, the SBOM and VEX pack, the support-period statement and the Annex V declaration.

Post-Quantum Migration Kit — the cryptography underneath all of it. One row per cryptographic use, the Mosca check that says whether you are already late, four migration waves, a vendor questionnaire with hard stops, and the deadline calendar from EO 14412 through CNSA 2.0 to 2035.

Why the fourth one belongs here. The CRA's Annex I asks you to protect confidentiality and integrity with state-of-the-art mechanisms and to ship an SBOM. EO 14412 commissioned a CBOM standard, NIST deprecates RSA-2048 and P-256 after 2030, and your support period almost certainly runs past that date. A product you CE-mark in 2027 with a ten-year support commitment is a product you have promised to keep cryptographically current into the 2030s — so the bill of materials and the crypto inventory are the same exercise done twice unless you do them together.

Sold as a Standard licence because two of the four components are sold that way. If you need Organization or vCISO/MSSP scope on the conformity or post-quantum kits, buy those directly.

What's included

  • PDF — fully editable
  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
One-time purchase
$517.00
  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-08