Cyber Resilience Act capability mapping
Maps the EU Cyber Resilience Act (CRA) requirements to SonarQube capabilities, including quality gates, Advanced Security, SBOM export, and dependency risk review.
Using SonarQube as CRA supporting evidence
CRA capability mapping
Annex I, Part I, point 2(a): No known exploitable vulnerabilities
Annex I, Part I, point 2(b): Secure by default configuration
Annex I, Part I, point 2(d): Secure access control
Annex I, Part I, point 2(e): Secure data transmission
Annex I, Part I, point 2(f): Integrity of data, commands, programs, and configuration
Annex I, Part I, point 2(h): Protect against denial-of-service attacks
Annex I, Part I, point 2(j): Limiting attack surfaces, including external interfaces
Annex I, Part II, point 1: Identification and documentation of vulnerabilities and components
Annex I, Part II, point 2: Addressing and remediating vulnerabilities without delay
Annex I, Part II, point 3: Effective and regular tests and reviews
Annex I, Part II, point 6: Sharing vulnerability information
Article 13(2) and 13(3): Cybersecurity risk assessment
Article 13(5): Due diligence on third-party components
Article 13(6) and 13(7): Component vulnerability handling and documentation
Related pages
Last updated
Was this helpful?

