Organisation

CRA compliance almost never fails on the technology. It fails on the organisation: nobody owns the decision to report, technical documentation is assembled after the product ships, and SBOMs are generated but never aggregated.

This section sets out who does what, with which tooling, on which timeline.

The starting point

One page conditions everything else: Generate and steer. It separates technical SBOM generation at application level — in the CI/CD chain, at every build — from centralisation for steering at organisation level, in a platform that re-evaluates the portfolio continuously.

The CRA requires both. Annex I, Part II, point 1 mandates the inventory; points 2, 3, 4 and 7 mandate a continuous process, which a file sitting next to an artefact cannot demonstrate.

The three trade-offs to settle explicitly

They belong to the committee, not to a team:

  1. Who decides to report within 24 hours? And who decides in their absence, on a Sunday?
  2. Who holds the right of veto over placing on the market when the technical documentation is incomplete?
  3. Who arbitrates between “fix” and “document in a VEX” when both are defensible?

Until those three answers are written down, compliance rests on individuals rather than on a process — and will not survive the first departure.

The pages in this section

They read in order: the tooling principle, the architecture that follows from it, the split of roles, the bodies that decide, the interface contract between the two teams, the metrics that measure, and the roadmap that sequences.

In this section

  • Cross-cutting

    Generate and steer: the two levels

    The founding distinction between technical SBOM generation at application level and centralisation for steering at organisation level. The CRA requires both.

  • Cyber

    Target architecture

    End-to-end flows from code repository to evidence vault; control points, data sovereignty, and three scenarios by maturity.

  • Cross-cutting

    Who does what — RACI matrix

    The split of roles across the twenty activities of the arrangement, and the three trade-offs the committee must settle explicitly.

  • Leadership

    Governance bodies

    CRA committee, PSIRT cell, pre-market review, licence policy review: composition, frequency, agenda and the decisions belonging to each level.

  • Cross-cutting

    Legal ↔ Cyber interface

    The interface contract between the two teams: cross deliverables with deadlines and formats, a shared vocabulary and an escalation path.

  • Leadership

    Metrics

    Coverage, performance, risk and readiness: which metrics to track, which to avoid, and a mock-up of the leadership dashboard.

  • Leadership

    Roadmap

    Six deployment waves, from scoping to continuous improvement, with milestones, deliverables and the dependencies between them.