This checklist documents the self-assessment of Lighthouse against the essential cybersecurity requirements of the EU Cyber Resilience Act (CRA) Annex I.
Assessment Information
Field
Value
Product
Lighthouse
Version Assessed
All versions from implementation date forward
CRA Classification
Standard product with digital elements
Assessment Date
2025-12-30
Assessor
Benjamin Huser-Berta (CRA Compliance Owner)
Next Review
2026-12-30
Part I: Security Requirements for Products with Digital Elements
1. Security by Design and Default
Req
Requirement
Status
Evidence / Notes
1.1
Products shall be designed, developed, and produced to ensure an appropriate level of cybersecurity
Security updates shall be available for expected lifetime
✅ Implemented
Latest version always supported
3. Software Bill of Materials (SBOM)
Req
Requirement
Status
Evidence / Notes
3.1
Maintain SBOM covering components and dependencies
✅ Implemented
SBOM generation workflow in ci_sbom.yml
3.2
SBOM in commonly used, machine-readable format
✅ Implemented
SPDX 2.2 (backend) + CycloneDX 1.5 (frontend)
3.3
SBOM available to users
✅ Implemented
Attached to GitHub Releases as Lighthouse-SBOM.zip
Part II: Vulnerability Handling Requirements for Manufacturers
1. Vulnerability Handling Process
Req
Requirement
Status
Evidence / Notes
1.1
Establish and maintain documented vulnerability handling process
✅ Implemented
PSIRT Process documentation
1.2
Provide contact point for vulnerability reports
✅ Implemented
security@letpeople.work
1.3
Take appropriate remediation measures
✅ Implemented
Security update policy
1.4
Apply effective policies for coordinated disclosure
✅ Implemented
SECURITY.md, 90-day disclosure policy
2. Documentation and Transparency
Req
Requirement
Status
Evidence / Notes
2.1
Provide users with clear security information
✅ Implemented
Security documentation, update policy
2.2
Provide information on how to report vulnerabilities
✅ Implemented
SECURITY.md, docs
2.3
Provide information on update mechanisms
✅ Implemented
Documentation, release notes
Assessment Summary
Category
Total
✅ Implemented
🔄 In Progress
❌ Not Started
Security by Design
9
9
0
0
Vulnerability Handling
7
7
0
0
SBOM
3
3
0
0
Manufacturer Obligations
7
7
0
0
Total
26
26
0
0
Open Items
No open items. All CRA Annex I requirements have been implemented.
Conclusion
Based on this self-assessment, Lighthouse fully meets the essential cybersecurity requirements of CRA Annex I for a standard product with digital elements.
Status: Ready for Declaration of Conformity signature.
Document Version: 1.0 Last Updated: 2025-12-30 Next Review: 2026-12-30