Enki Tech resource · CRA incident readiness
CRA 24/72h Incident Dry-Run Checklist
A compact technical checklist for testing whether an organisation can move from awareness of an actively exploited vulnerability or severe product-security incident to owned decisions, reporting data, remediation and evidence.
How to use it
Run the workflow against one realistic scenario and use a clock
The objective is not to debate legal interpretation during the exercise. The objective is to expose operational delay: missing product mapping, unclear authority, unavailable evidence, fragile handoffs and remediation steps that depend on a single person.
Simple readiness scoring
Score the process—not the team
Evidence principle
If evidence requires a two-week audit scramble, it is not 24-hour ready.
The strongest remediation opportunities usually sit between tools and teams: vulnerability intelligence that is not linked to product inventory, tickets without clear authority, evidence that lives in screenshots, or decisions that depend on one senior engineer being available.
Scope boundary
Technical readiness is only one part of CRA compliance
This checklist is an operational engineering aid. It does not provide legal advice, determine reportability on behalf of a manufacturer, submit notifications, or certify compliance. Legal interpretation and regulatory responsibility remain with the manufacturer and its authorised advisers.
