CRA Publication Preflight

This page is for operators preparing Stella’s own product-security disclosures under the EU Cyber Resilience Act. CRA publication preflight separates local evidence readiness (can the pack produce a deterministic artifact?) from live public publication readiness (are the public mailbox, intake key, advisory route, and lifecycle records verified?). The two are reported as independent lines so a blocked public preflight never silently blocks local evidence work.

Claim boundary: manufacturer-self for Stella product-security publication.

Publication preflight is a gate, not an exporter: it checks public-facing inputs. The deterministic evidence bundle itself is produced by the CRA technical file surface, and both belong to the CRA Assurance Packs.

Source Docs

Readiness Lines

Readiness lineMeaning
Local signed export readinessThe pack can produce a deterministic local evidence or advisory artifact.
Live public publication readinessPublic metadata, routes, mailbox, key lineage, and support lifecycle records are verified for publication.

These lines must be shown separately in setup, CLI, and Web surfaces. A blocked public publication preflight must not block CRA technical-file generation.

Required Public Inputs

The preflight should verify at least:

Private keys, mailbox credentials, and provider secrets must never appear in setup responses, logs, or CLI output.

Setup Wizard Handoff

The optional setup assurance step shows CRA Product Security readiness as two separate lines:

The live-publication line must mention mailbox delivery/access, a non-expired encryption-capable intake key certified by website lineage, product-security rotation roles, and support lifecycle/publication metadata. It must not tell customer tenants to configure Stella’s manufacturer mailbox for their own local evidence packs.

Change Log

Date (UTC)Update
2026-06-16Reconciled to verified code: ExportCenter and Notify report local signed-export readiness separately from live-publication readiness (signedExportReady/livePublicationReady, operatorHandoffReady/autoSubmitReady), so a blocked public preflight never blocks local evidence. The remaining live-publication blockers are operational/process (mailbox delivery+access, non-expired intake key, rotation, support-lifecycle metadata) — tracked as G4 in cra-gap-closure-plan.md and CRA-Q1 in decisions-log.md, not a code gap.