CRA RACI Matrix

Role responsibilities for Cyber Resilience Act compliance

A RACI matrix clarifies who does what for each CRA obligation. Clear ownership prevents gaps and duplication, especially important given the regulation's broad scope across engineering, security, legal, and business functions.

Note: The CRA places obligations on "manufacturers" as a legal entity—it does not prescribe internal organizational roles. This matrix is a suggested starting point based on common industry practices, not a regulatory requirement. Adapt it to your organization's structure, size, and existing processes.

RACI Definitions

R

Responsible

Does the work

A

Accountable

Ultimate owner / sign-off

C

Consulted

Provides input

I

Informed

Kept aware

Governance & Regulatory RACI

Obligation Area Eng Sec Legal Prod QA Ops Supply Support Exec
Secure SDLC implementationRAICCIIII
Threat modeling & risk assessmentCR/AICIIIII
SBOM generation & maintenanceRAICIICII
Vulnerability handling (PSIRT)CR/ACIICICI
Coordinated vulnerability disclosureIR/ACIIIIRI
Technical documentationRCCCAIIII
Conformity assessment selectionCCCIRIIIA
CE marking readinessCCCIR/AIIII
Post-market monitoringRACCCRICI
24h incident notificationIR/ACIICIII
Regulatory communicationICRICIIIA
Product security roadmapCCIR/AIIIII
Support period definitionCCCR/AIIIII
User notification of vulnerabilitiesIRCCICIAI
Supply chain due diligenceCCCCCIR/AII
Record keeping (10-year)CCRIACCII
Training & competencyCRIICCIIA

Security Features & Controls RACI

Security Control Eng Sec Legal Prod QA Ops Supply Support Exec
Secure-by-default configurationRAICCIIII
Authentication & access controlRAICCIIII
Encryption (at rest / in transit)RAICCIIII
Secure update mechanismRAICCRIII
Vulnerability remediationRAICCRIII
Logging & security eventsRAICCCIII
Known vulnerability protectionRAICCCIII
Hardening guidanceRCIACIICI
SBOM & dependency controlRAICCIRII
End-of-life support policyCCRAIIICI
Secure design reviewsCR/AICCIIII
Penetration testingCR/AIICIIII
Third-party component assessmentCR/AICCIRII

Role Definitions

Engineering

Development teams building and maintaining the product

Security

Product security team, PSIRT, security architects

Legal

Legal counsel, regulatory affairs

Product

Product management, product owners

QA/Quality

Quality assurance, compliance, conformity assessment

Operations

IT operations, deployment, infrastructure

Supply Chain

Procurement, vendor management, component sourcing

Customer Support

Customer-facing support, vulnerability report intake

Executive

C-level, senior leadership with business accountability

Implementation Notes

  • Smaller organizations may combine roles (e.g., Security + QA, Legal + Compliance)
  • For audit readiness, maintain a CRA Security Control Register mapping each control to evidence artifacts
  • The 24h incident notification applies to actively exploited vulnerabilities and requires pre-established ENISA/CSIRT channels
  • Review and update role assignments annually or when organizational structure changes