Be CRA-ready before 2027

The CRA makes manufacturers accountable for the cybersecurity of their products, regardless of how the code was created. SonarQube gives teams an automated verification layer to identify vulnerabilities early, enforce security standards, and ship with confidence.

Understanding the regulation

What is the Cyber Resilience Act?

Global reach image

Global reach

Broad scope image

Broad scope

warning

Severe penalties

ai

AI code is your liability

Key dates

The compliance clock is running

CRA obligations roll out in stages. Organizations need to begin preparing now — particularly for the vulnerability reporting deadline that arrives in September 2026.

December 2024

CRA enters into force

September 11, 2026

Reporting obligations for actively exploited vulnerabilities and severe incidents become mandatory

December 11, 2027

The CRA becomes generally applicable to in-scope products with digital elements made available on the EU market
Product capabilities

Streamlined operational compliance for key CRA requirements

SonarQube brings together code quality, application security, dependency visibility, and release controls in a single developer-friendly platform across your SDLC.

pdf

Dedicated CRA Compliance Report

A purpose-built report that maps your entire codebase against specific CRA Annex I requirements, giving security and compliance teams instant visibility into their compliance posture and shareable evidence for regulators.
magnifying glass

Advanced SAST

Deep, cross-procedural static analysis across 30+ languages detects security vulnerabilities including OWASP Top 10, CWE Top 25, and custom rule sets aligned to your risk profile.
automatic

Software Composition Analysis (SCA)

Continuous scanning of all open-source dependencies against NVD, EPSS, KEV, and OSV databases.
code

Automated SBOM Generation

Generate machine-readable Software Bills of Materials with a single click, providing the traceable dependency inventory the CRA explicitly mandates for every product.
lock

Secrets Detection

Industry-leading detection of 450+ secret types with a sub-1% false positive rate. Blocks hard-coded credentials from reaching repositories or AI coding agents before they become a breach risk.
settings

Quality Gates & Profiles

Enforce your exact compliance and quality rules consistently across every developer and every AI coding tool. Automatically block non-compliant code from merging — with full audit trail generation.
Increase-white-on-dark.svg

Built-in Compliance Reports

Out-of-the-box reports for OWASP Top 10, OWASP ASVS, PCI DSS, CWE Top 25, STIG, MISRA C++:2023, and now the Cyber Resilience Act — all available within your existing workflow.
secure

Dependency Risk Governance

Go beyond detection with review, assignment, status tracking, fix guidance, license-policy enforcement, and malicious-package alerts for third-party dependencies.
Your action plan

8 steps to CRA compliance with SonarQube

Download CRA checklist

1. Minimize vulnerabilities through SAST

2. Safeguard system access

3. Assess open-source risk continuously

4. Verify absence of known exploits

5. Master supply chain transparency

6. Generate audit trails and proof

7. Enforce standards at point of creation

8. Assess risk with strategic governance

Build your CRA compliance case today

SonarQube gives compliance and security teams the automated infrastructure to prove readiness — without slowing down development.

SAST SCA SBOM Secrets Detection CRA Report OWASP Top 10 CWE Top 25 PCI DSS