Skip to main content

The Compliance Obligation Matrix

Navigating the complex landscape of cybersecurity regulations requires a clear understanding of your specific legal and operational responsibilities. The CVD Portal includes a dynamic Compliance Obligation Matrix, a centralized dashboard designed to map your vulnerability management activities directly to the specific mandates of the Cyber Resilience Act (CRA) and other relevant frameworks.

This matrix breaks down broad regulatory requirements into specific, actionable tasks and measurable Service Level Agreements (SLAs). For example, it tracks your adherence to mandatory reporting timelines (e.g., the 24-hour early warning requirement under Article 14 of the CRA), the completeness of your SBOM registry, and the consistency of your vulnerability disclosure policies. The matrix provides real-time visibility into your compliance status, highlighting areas where you are at risk of falling out of adherence.

By translating complex legal jargon into operational metrics, the Obligation Matrix empowers your security and compliance teams to proactively manage regulatory risk. It serves as the single source of truth for demonstrating your compliance posture to internal stakeholders, auditors, and regulatory bodies, ensuring that your CVD program meets the highest legal standards.

Applicability by organizational role

The Cyber Resilience Act creates distinct obligations for different supply-chain roles. Configure your roles under Settings.

Select one or more roles from the five defined under Article 3.

  1. Manufacturer (Article 3(13)). Develops or markets products under its own name or trademark.
  2. Importer (Article 3(16)). Places products from outside the European Union on the market.
  3. Distributor (Article 3(17)). Makes products available on the market without modification.
  4. Open Source Software Steward (Article 3(14)). Provides sustained support for open-source development.
  5. Authorised Representative (Article 18). Acts under written mandate for a non-EU manufacturer.

When an organization holds several roles, the portal applies the most demanding status across all held roles. The precedence order is required, then verify only, then recommended, then optional, then not applicable.

Under Article 21, importers and distributors who place products under their own trademark or make substantial modifications assume all manufacturer obligations. The portal includes an explicit Article 21 question that adds the manufacturer role when answered yes.

Non-applicable sections leave the readiness denominator completely. A distributor does not build products, so SBOM and SDLC obligations are marked not applicable.

Implementation roadmap

The Readiness page displays the OpenChain implementation roadmap. The roadmap provides a structured thirteen-phase schedule toward complete CRA readiness.

The PRIORITY row targets 11 September 2026 as a statutory deadline for Article 14 notification procedures. All subsequent phases provide relative target windows anchored to your organization start date.

Phase completion is calculated directly from your control register rows. When you update controls in your register, roadmap progress updates automatically.

Checklist items are adapted from the OpenChain CRA Compliance Checklist (Release Candidate 1, 19 August 2026), under CC BY 4.0. Completing checklist items does not constitute a formal conformity assessment or an EU Declaration of Conformity.