Skip to content
NarrowForge

NF / Guide / Security

Cyber Resilience Act evidence — what operational tooling can actually do

CRA scrutiny rewards a boring, complete trail: what shipped, what was known, what was fixed, when.

2026-07-10

Evidence, not promises

Under the EU Cyber Resilience Act, the question is rarely whether you care about security. It is whether you can show the trail: releases, vulnerability handling, decisions, timelines.

The minimum useful pack

  • Versioned release ledger.
  • Vulnerability intake → fix → release linkage.
  • SBOM references per release.
  • Decision log for exceptions and risk acceptances.

Where GitHub fits

Engineering already records most of this in repos, releases and advisories. The gap is assembly: scattered signals, assembled under pressure. GitHub-native evidence tooling closes that gap without asking teams to live in a second system.

Related: ForgeVault CRA

Operational background, not legal advice. Confirm CRA obligations with counsel.

Related guides

Compliance · 2026-08-12

How Intrastat dispatches work for Shopify merchants in Spain

What Intrastat actually asks for, where Shopify order data fits, and how to run a calm monthly review.

Read guide

Operations · 2026-07-28

Jira workflow validation checklist

The readiness checks teams actually need before work moves forward — and how to encode them.

Read guide