MeshanicsDocs
CRA & compliance

CRA secure updates

The Cyber Resilience Act places obligations on manufacturers, not on an OTA tool. Meshanics supplies mechanisms and recorded facts that a manufacturer can use in its secure-update process and technical documentation.

Evidence produced by the delivery path

  • a customer-authorized, signed release manifest fixing artifact identities and order;
  • TUF metadata that authorizes exact hashes, lengths, versions and freshness;
  • rollout approvals, canary waves, health outcomes, halts and recovery results;
  • device-signed release receipts with software-held assurance;
  • a product record connecting support period, affected versions, risk review and substantial-change decisions;
  • an issued evidence package whose included bytes can be verified offline.

Manufacturer decisions that remain outside Meshanics

The manufacturer defines intended purpose, classification, support period, risk acceptance, conformity route, coordinated disclosure and regulator submissions. Meshanics does not declare conformity or start a legal reporting clock automatically from a scanner match.

Continue with CRA overview and timeline, CRA SBOM, and CRA vulnerability reporting.