REGULATION (EU) 2024 / CYBER RESILIENCE ACT (CRA)

EU Cyber Resilience Act for Telecom Equipment & 5G CNFs

Automated CE mark cybersecurity certification, Software Bill of Materials (SBOM) generation, and statutory 24-hour vulnerability reporting for carrier hardware and cloud-native network functions.

REQUIREMENT 1

Security-by-Design & Default

Mandatory zero-trust baseline configuration for network elements, Base Transceiver Stations (BTS), and eSIM Remote SIM Provisioning (RSP) nodes.

✓ Verified via Asset Profiler
REQUIREMENT 2

Automated CycloneDX SBOM

Real-time tracking of open-source and proprietary software dependencies across 5G User Plane Functions (UPF) and Open RAN DU/CU codebases.

✓ CycloneDX v1.5 JSON Export
REQUIREMENT 3

24-Hour ENISA Incident Reporting

Direct STIX 2.1 integration for reporting actively exploited vulnerabilities in telecommunication products to ENISA and national CSIRTs within 24 hours.

✓ Integrated CSIRT Exporter
📦

CycloneDX v1.5 Telecom SBOM Explorer

CRA Article 10 Mandatory Technical Documentation & Vulnerability Ledger

Component / LibraryTypeLicenseCRA Essential ControlsKnown CVEsCE Status
dpdk-kni
pkg:generic/dpdk@23.11?vlan=true
FrameworkBSD-3-Clause
Memory Bounds Check & Zeroization
0 VULNS✓ CE CONFORMANT
openssl-fips
pkg:generic/openssl@3.0.12?fips=140-3
CryptographicApache-2.0
Hardware TRNG & Post-Quantum KEM
0 VULNS✓ CE CONFORMANT
libgtp5g
pkg:github/free5gc/gtp5g@0.8.4
Kernel DriverGPL-2.0
TEID Randomization (GSMA FS.37)
0 VULNS✓ CE CONFORMANT
json-c
pkg:generic/json-c@0.17
LibraryMIT
Strict Schema Validator (CRA Art. 10)
0 VULNS✓ CE CONFORMANT

Connect Your Telecom Pipeline to TelcoSec CRA Engine

Integrate continuous CycloneDX SBOM exports into your CI/CD delivery pipeline and automate statutory ENISA Article 11 vulnerability notifications.