Cyber Resilience Act

What NODE64 contributes to your CRA preparation — and what it explicitly is not.

The deadlines

The Cyber Resilience Act applies to manufacturers of products with digital elements placed on the EU market, regardless of where the company is based. It phases in:

Date What applies
11.09.2026 Reporting obligation for actively exploited vulnerabilities and severe incidents: early warning within 24 hours, follow-up within 72 hours, final report 14 days after the security update.
11.12.2026 Sufficient notified conformity assessment bodies must be available.
11.12.2027 All remaining requirements: security by design, technical documentation, software bill of materials (SBOM).

What NODE64 contributes

Four things the CRA asks of you that NODE64 takes off your hands — not as an assurance of conformity, but as material for it:

  • An inventory of your systems: which packages at which version run where, across the whole fleet.
  • The vulnerability picture for it, from the distributions' own advisories — with urgency from the exploitation catalogues (EUVD, CISA KEV) and EPSS rather than from the score alone.
  • Evidence reports as PDF, optionally with an audit cut: fixed findings, relapses, period, scope.
  • An account audit log recording who decided what and when — including the decision to accept a risk.

What NODE64 is not

This is the more important section, which is why it sits here and not in the small print:

  • No conformity assessment. Whether your product meets the requirements is determined by you or a notified body — no tool can do that.
  • No legal advice. Whether the CRA applies to your product at all, whether an exemption applies, and which transitional rule covers versions already distributed are legal questions. We do not answer them.
  • No reporting on your behalf. NODE64 reports nothing to ENISA or the BSI. The obligation is yours, and the 24-hour clock runs for you.
  • No completeness. What is recorded is what the package manager installed. A tarball under /opt, a self-built binary or an embedded library appears in no package list — and therefore in none of our reports.

And what we do ourselves

The agent is a product with digital elements — so the CRA applies to us too. What follows from that is public:

  • For every agent release, a bill of materials in CycloneDX 1.6 (BSI TR-03183 Part 2), signed along with the binaries themselves: get.node64.de
  • The same matching machinery that works on your systems runs daily over our own dependencies.
  • A named route for reports from outside, with promises we can keep: Report a vulnerability

Basis: BSI TR-03183, Verordnung (EU) 2024/2847.