Be CRA-ready before September 2026
The CRA makes manufacturers accountable for the cybersecurity of their products, regardless of how the code was created. SonarQube gives teams an automated verification layer to identify vulnerabilities early, enforce security standards, and ship with confidence.
What is the Cyber Resilience Act?
The EU Cyber Resilience Act, (Regulation EU 2024/2847), sets mandatory cybersecurity requirements for in-scope products with digital elements made available on the EU market, regardless of whether the manufacturer is based in the EU.
Global reach
Applies to manufacturers of in-scope products with digital elements made available on the EU market, including manufacturers based outside the EU.
Broad scope
Covers many software and hardware products with digital elements, including B2B software products, consumer electronics, connected devices, and components.
Severe penalties
Non-compliance can result in fines up to €15 million or 2,5% of global annual turnover, whichever is higher.
AI code is your liability
The CRA makes no distinction between human-written and AI-generated code; you’re responsible for all of it.
The compliance clock is running
CRA obligations roll out in stages. Organizations need to begin preparing now — particularly for the vulnerability reporting deadline that arrives in September 2026.
December 2024
September 11, 2026
December 11, 2027
Streamlined operational compliance for key CRA requirements
SonarQube brings together code quality, application security, dependency visibility, and release controls in a single developer-friendly platform across your SDLC.
Dedicated CRA Compliance Report
Advanced SAST
Software Composition Analysis (SCA)
Automated SBOM Generation
Secrets Detection
Quality Gates & Profiles
Built-in Compliance Reports
Dependency Risk Governance
8 steps to CRA compliance with SonarQube
A practical checklist based on Annex I requirements — mapped to the SonarQube capabilities that automate each step.
1. Minimize vulnerabilities through SAST
Identify exploitable weaknesses early in development, satisfying the Article 13 mandate to minimize vulnerabilities before products reach market.
2. Safeguard system access
Scan the entire codebase to detect and block hard-coded API keys, passwords, and sensitive tokens, fulfilling the Annex I unauthorized access requirement.
3. Assess open-source risk continuously
Continuously monitor all third-party dependencies for known CVEs, supporting CRA obligations for transparency and lifecycle risk management.
4. Verify absence of known exploits
Utilize NVD, EPSS, KEV, and OSV databases to verify components are free from known risks — directly addressing the Annex I mandate to ship without known exploitable vulnerabilities.
5. Master supply chain transparency
Auto-generate machine-readable SBOMs to ensure a traceable inventory management process, meeting explicit CRA supply chain mandates.
6. Generate audit trails and proof
Maintain secure audit logs capturing lifecycle changes, configuration updates, and security events — simplifying CRA risk assessment documentation.
7. Enforce standards at point of creation
Empower developers with IDE feedback and configurable quality gates to ensure no non-compliant code ever proceeds to production.
8. Assess risk with strategic governance
Leverage portfolio dashboards for a high-level view of organizational compliance posture, transforming invisible code debt into visible data for security and risk leaders.
Additional resources
The Cyber Resilience Act: Why AI velocity demands automated verification
Read more
Cyber Resilience Act: Navigating speed and security with AI-coding
Read more
Cyber Resilience Act by industry: Who is affected and who is exempt?
Read more
Tools you need for a CRA-ready codebase
Read more
Cyber Resilience Act compliance for AI-generated code
Read more
Build your CRA compliance case today
SonarQube gives compliance and security teams the automated infrastructure to prove readiness — without slowing down development.