Foundational
- Structured dependency list
- Major release updates
- Linked to release documentation
CRA Adoption Best Practices
The SME Practical Implementation Toolkit: lightweight checklists and templates to tick online, print, or download into the tools you already use.
Reusable templates and practical guidance to help SMEs implement a proportionate and lifecycle-oriented approach to integrating FOSS components under the CRA. The tools are intentionally lightweight and scale with product criticality, exposure, and available resources.
Tick the checklists online (your progress stays in this browser), print them, or download the templates into the tool you already use: a spreadsheet, a wiki, or a Git repository.
A one-page baseline of practices that most SMEs can implement to support CRA-aligned integration of open source components. Designed for limited time and resources; strengthen it proportionally based on risk.
Clear ownership prevents security responsibilities from becoming implicit or unassigned.
Visibility is the foundation of risk-based management.
Your ticks are only saved in this browser.
MVC principle
Start small, be consistent, and scale controls based on risk.
Twelve questions to ask before integrating a FOSS component. It does not replace a structured risk assessment, but offers an accessible and proportionate entry point for SMEs with limited resources.
Your ticks are only saved in this browser.
Component handles sensitive functions or is exposed to the internet? Use the decision matrix to find the due diligence level it needs.
A simple register of the open source components integrated into your product. It supports traceability, due diligence, and lifecycle monitoring, and can be maintained in a spreadsheet, SharePoint, Git, or any internal tool.
Example (filled row)
| Component name | Version | Used in | Criticality | Exposure | License | Maintainer activity | Last vulnerability review | Update owner | Notes |
|---|---|---|---|---|---|---|---|---|---|
| ExampleAuthLib | 2.4.1 | Authentication module | High | Public | MIT | Active (monthly releases) | 12 Feb 2026 | CTO | Security-sensitive. CVE-2025-XXXX patched in v2.4.1. Continuous monitoring enabled. |
For medium and high criticality components, or any publicly exposed component. It complements the component register by documenting why the component was selected and what monitoring is in place.
Your ticks are only saved in this browser.
A structured but lightweight, SME-sized vulnerability workflow, from the first alert to close-out.
Your ticks are only saved in this browser.
A short-form policy defining how third-party dependencies are reviewed, updated, and retired. One page is enough.
What to capture in a Software Bill of Materials, and when. An SBOM supports transparency and traceability for products using FOSS components, and SBOM practices can be adopted progressively.
Your ticks are only saved in this browser.
The OCCTET toolchain scans your source code and generates SBOMs automatically, helping you move from level 1 to level 3.