Skip to main content

Regulation overview

The Cyber Resilience Act (CRA) is an EU regulation that establishes cybersecurity requirements for products with digital elements. It entered into force in December 2024, with full compliance required by December 2027.

TinyBell’s classification

AspectClassification
Product typeProduct with Digital Elements (PDE)
Risk categoryDefault (standard risk)
RoleManufacturer
Conformity assessmentModule A (self-assessment)
TinyBell is classified as a default risk product because it does not manage critical network functions, privileged access control, or large-scale identity management.

Compliance status

Requirements met

Security by design

The platform is built with input sanitization, CSRF protection, encrypted connections, and secure defaults.

Security by default

Accounts are created with secure configurations. Weak passwords are rejected. 2FA is available.

SBOM maintained

A complete Software Bill of Materials is maintained and updated with each release.

Vulnerability disclosure

A public vulnerability disclosure channel is active at info@thetinybell.com.

Data minimization

The pixel collects only the data necessary for notification targeting. No personal identifiers.

Secure updates

Security updates are delivered automatically. No action required by hotel customers.

Incident reporting timeline

As required by Article 14 of the CRA, TinyBell follows this notification schedule for actively exploited vulnerabilities:
TimeframeActionAuthority
24 hoursEarly warning with initial severity assessmentENISA + INCIBE
72 hoursDetailed technical notification with affected products and initial fixesENISA + INCIBE
1 monthFinal report with root cause analysis and remediationENISA + INCIBE
These obligations apply from September 11, 2026. TinyBell has implemented internal processes to meet these deadlines.

Support period

TinyBell commits to a minimum 5-year support period from the date of each product version release. During this period:
  • Security updates are provided free of charge
  • Vulnerabilities are monitored continuously
  • Patches are delivered within 7 days for critical issues

Technical documentation

The following technical documentation is maintained as part of our CRA compliance:
  1. Risk assessment: Formal analysis of threats and mitigations
  2. System architecture: Data flow diagrams and interface descriptions
  3. SBOM: Complete inventory of components and dependencies
  4. User instructions: Documentation on secure operation (this docs site)
  5. Conformity declaration: EU declaration of conformity (available upon request)

Contact

For CRA-related inquiries or to request documentation: info@thetinybell.com Subject line: [CRA] followed by your request.