# EU Cyber Resilience Act (CRA) hub

> Guidance for manufacturers of products with digital elements: inventory, SBOM, vulnerability handling, and Article 14 readiness.

## What this hub covers

- Manufacturer duties under the CRA for products with digital elements
- Product SBOM and continuous vulnerability awareness
- Article 14 reporting to CSIRT/ENISA from **11 September 2026**
- Evidence and readiness toward December 2027 obligations
- Build-environment SBOM and the rebuild path when a patch is required

## Key spokes

- [Vulnerability handling / Article 14](https://www.alloy-it.io/compliance/cyber-resilience-act/vulnerability-handling/)
- [Compliance checklist](https://www.alloy-it.io/compliance/cyber-resilience-act/compliance-checklist/)
- [SBOM](https://www.alloy-it.io/compliance/cyber-resilience-act/sbom/)
- [Build-environment SBOM](https://www.alloy-it.io/compliance/cyber-resilience-act/build-environment-sbom/)
- [Embedded firmware](https://www.alloy-it.io/compliance/cyber-resilience-act/embedded-firmware/)

## How alloy-it maps

Monitor → Notify authorities → Trace back → Reproduce. Alloy prepares Article 14 evidence and SRP JSON; it does **not** submit to ENISA and is **not** CE-marking software.

## Links

- [HTML CRA hub](https://www.alloy-it.io/compliance/cyber-resilience-act/)
- [Get started](https://www.alloy-it.io/get-started/index.md)
- [Product](https://www.alloy-it.io/product/index.md)
- [llms.txt](https://www.alloy-it.io/llms.txt)
