Cyber Resilience Act Gap FinderProduct list reading ยท Regulation (EU) 2024/2847, UK PSTI, Cal. Civ. Code 1798.91.04

The Cyber Resilience Act: what it asks of a product list

Regulation (EU) 2024/2847 binds products with digital elements made available on the EU market. Article 14 (reporting actively exploited vulnerabilities and severe incidents) applies from 11 September 2026, including to products placed on the market before 11 December 2027; Chapter IV (notified bodies) from 11 June 2026; the rest from 11 December 2027 (Art. 71(2), Art. 69(3)). A product's class follows the core function it has: Annex III (important, class I and II), Annex IV (critical), otherwise default.

Read from the held text: Article 71(2) sets the dates, Article 69(3) brings products placed on the market before 11 December 2027 under the reporting duty, Article 69(2) subjects them otherwise only on a substantial modification, and Article 2 takes out medical devices, in vitro diagnostics, vehicle systems under type approval, certificate-holding aviation equipment, marine equipment, identical spare parts and products made exclusively for national security or defence. Named, not quoted, beside it: Commission Implementing Regulation (EU) 2025/2392, the technical descriptions of the Annex III and IV categories; harmonised standards under the Cyber Resilience Act.

Duties by role

RoleClauses
manufacturerCRA Art. 6 Condition for making a product available on the market
CRA Art. 13(1) Design, development and production to Annex I Part I
CRA Art. 13(2) Cybersecurity risk assessment used across the product lifecycle
CRA Art. 13(8) first subparagraph Effective vulnerability handling for the support period
CRA Art. 13(8) third subparagraph Minimum support period of five years
CRA Art. 13(12) second subparagraph Carrying out the conformity assessment procedure
CRA Art. 13(12) third subparagraph EU declaration of conformity and CE marking after demonstrated conformity
CRA Art. 13(17) Single point of contact for users
CRA Art. 13(19) End date of the support period stated at purchase, and end-of-support notice
CRA Art. 14(1) Notifying actively exploited vulnerabilities to the CSIRT and ENISA
CRA Art. 14(3) Notifying severe incidents affecting product security
CRA Annex I Part I(1) Appropriate level of cybersecurity based on the risks
CRA Annex I Part II(1) Identify and document vulnerabilities and components, including an SBOM
CRA Annex I Part II(5) Coordinated vulnerability disclosure policy
CRA Art. 31(1) Content of the technical documentation
CRA Art. 28(1)-(2) Drawing up and maintaining the EU declaration of conformity
CRA Art. 30(1)-(2) Affixing the CE marking
importerCRA Art. 6 Condition for making a product available on the market
CRA Art. 19(1) Importers place only conforming products on the market
CRA Art. 19(2) Importer checks before placing on the market
CRA Art. 19(6) Importer retention of the declaration and access to technical documentation
distributorCRA Art. 6 Condition for making a product available on the market
CRA Art. 20(1) Distributors act with due care
CRA Art. 20(2) Distributor verification before making available
own brand (becomes the manufacturer)CRA Art. 21 Importers and distributors who become manufacturers
CRA Art. 13(1) Design, development and production to Annex I Part I
CRA Art. 13(8) first subparagraph Effective vulnerability handling for the support period
CRA Art. 13(8) third subparagraph Minimum support period of five years
CRA Art. 14(1) Notifying actively exploited vulnerabilities to the CSIRT and ENISA
CRA Art. 14(3) Notifying severe incidents affecting product security
CRA Annex I Part II(1) Identify and document vulnerabilities and components, including an SBOM
CRA Art. 28(1)-(2) Drawing up and maintaining the EU declaration of conformity
CRA Art. 30(1)-(2) Affixing the CE marking

Notes that cite it

NoteClause
1. Declared function points to a critical product, and the route planned is not one Art. 32(4) setsCRA Art. 32(4)
CRA Art. 8(1)
CRA Art. 32(3)
2. Important class II function with self-assessment, or no notified body, plannedCRA Art. 32(3)
CRA Art. 7(1)
3. Important class I function with self-assessment plannedCRA Art. 32(2)
CRA Art. 7(1)
CRA Art. 32(1)
4. No process to report an actively exploited vulnerability or a severe incidentCRA Art. 14(1)
CRA Art. 14(2)(a)
CRA Art. 14(2)(b)
CRA Art. 14(3)
CRA Art. 14(8)
CRA Annex I Part II(5)
CRA Art. 13(8) sixth subparagraph
CRA Annex I Part II(6)
CRA Art. 13(17)
5. No support period stated, or under five years with no reason recordedCRA Art. 13(8) third subparagraph
CRA Art. 13(8) second subparagraph
CRA Art. 13(8) first subparagraph
CRA Art. 13(19)
CRA Annex II 7
CRA Annex II 2
6. A universal default passwordCRA Annex I Part I(2)(b)
CRA Annex I Part I(2)(d)
7. No published vulnerability contactCRA Annex I Part II(6)
CRA Art. 13(17)
CRA Annex I Part II(5)
CRA Art. 13(8) sixth subparagraph
CRA Annex II 7
CRA Annex II 2
8. No security update mechanism, or unsigned updatesCRA Annex I Part I(2)(c)
CRA Annex I Part II(7)
CRA Annex I Part I(2)(f)
CRA Annex I Part II(8)
CRA Art. 13(9)
CRA Annex I Part II(2)
9. No software bill of materials kept, or partialCRA Annex I Part II(1)
CRA Art. 13(8) third subparagraph
CRA Art. 13(8) second subparagraph
CRA Art. 13(8) first subparagraph
CRA Art. 31(1)
CRA Art. 31(2)
CRA Annex VII 4
11. Manufacturer outside the EU with no authorised representativeCRA Art. 18(1)-(2)
CRA Art. 18(3)
CRA Art. 19(2)
CRA Art. 19(6)
12. Still on sale for 11 December 2027 with no conformity route plannedCRA Art. 32(1)
CRA Art. 28(1)-(2)
CRA Art. 30(1)-(2)
CRA Art. 31(1)
CRA Art. 31(2)
CRA Annex VII 4
14. Content where a label belongsCRA Art. 31(1)
CRA Art. 31(2)
CRA Annex VII 4
CRA Art. 13(8) third subparagraph
CRA Art. 13(8) second subparagraph
CRA Art. 13(8) first subparagraph

CRA: every clause cited

51 of the 140 held

The requirement text is our statement of each clause, read against the copy we hold and cited to it; it is not the instrument verbatim.

CRA Annex I Part I(1)Appropriate level of cybersecurity based on the risks

Products must be designed, developed and produced so that they ensure a level of cybersecurity appropriate to the risks identified.

What a notified body or authority asks to see: Risk-to-control rationale showing why the chosen security level fits the identified risks; Threat model
Where lists usually fall short: Security level copied from another product with a different risk profile
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part I(2)(b)Secure by default configuration with reset to original state

The product must ship with a secure by default configuration, unless otherwise agreed with a business user for a tailor-made product, and must allow the product to be reset to its original state.

What a notified body or authority asks to see: Default configuration specification and hardening baseline; Test evidence of factory reset restoring secure defaults; Records of any tailor-made agreements departing from secure defaults
Where lists usually fall short: Universal default passwords or open debug services enabled out of the box; Reset restores insecure settings
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part I(2)(c)Vulnerabilities addressable through security updates, automatic by default

The product must allow vulnerabilities to be addressed through security updates, including, where applicable, automatic security updates installed within an appropriate time and enabled by default with a clear, easy opt-out, notification to users of available updates, and the option to postpone them temporarily.

What a notified body or authority asks to see: Update mechanism design; Default settings showing automatic security updates on; User interface evidence of opt-out, notification and postpone options
Where lists usually fall short: No update path for deployed devices; Automatic updates off by default with no justification in the risk assessment
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part I(2)(d)Protection from unauthorised access and reporting of it

The product must protect against unauthorised access through appropriate control mechanisms, including authentication, identity or access management systems, and report on possible unauthorised access.

What a notified body or authority asks to see: Authentication and authorisation design; Brute force and credential test results; Logging or alerting of failed or suspicious access attempts
Where lists usually fall short: Local interfaces left unauthenticated; Failed access never surfaced to the user or operator
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part I(2)(f)Integrity of data, commands, programs and configuration

The product must protect the integrity of stored, transmitted or processed data, commands, programs and configuration against manipulation or modification the user has not authorised, and report on corruptions.

What a notified body or authority asks to see: Secure boot and code signing design; Integrity checks on configuration and messages; Evidence of corruption detection and reporting
Where lists usually fall short: Firmware accepted without signature verification; Configuration files modifiable without detection
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part II(1)Identify and document vulnerabilities and components, including an SBOM

Manufacturers must identify and document the vulnerabilities and components in the product, including by drawing up a software bill of materials in a commonly used, machine-readable format covering at least the top-level dependencies.

What a notified body or authority asks to see: SBOM in SPDX or CycloneDX per released version; Process tying SBOM generation to the build; Vulnerability records linked to SBOM components
Where lists usually fall short: SBOM produced once and not regenerated per release; Hardware and firmware components missing from the inventory
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part II(2)Address and remediate vulnerabilities without delay, security updates separate from features

Manufacturers must address and remediate vulnerabilities without delay in relation to the risks, including by providing security updates, and where technically feasible must provide new security updates separately from functionality updates.

What a notified body or authority asks to see: Remediation timelines by severity; Release history showing security-only updates; Metrics on time to remediate
Where lists usually fall short: Security fixes held back for the next feature release
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part II(5)Coordinated vulnerability disclosure policy

Manufacturers must put in place and enforce a policy on coordinated vulnerability disclosure.

What a notified body or authority asks to see: Published CVD policy (for example aligned with ISO/IEC 29147 and 30111); Evidence of the policy applied to real reports
Where lists usually fall short: Policy published but reports go unanswered
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part II(6)Facilitating vulnerability information sharing, with a contact address

Manufacturers must take measures to facilitate sharing of information on potential vulnerabilities in the product and its third-party components, including providing a contact address for reporting vulnerabilities.

What a notified body or authority asks to see: Security contact address (for example security.txt); Participation in information sharing on third-party components
Where lists usually fall short: Contact address not monitored
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part II(7)Secure distribution of updates

Manufacturers must provide mechanisms to distribute updates securely so vulnerabilities are fixed or mitigated in time and, where applicable for security updates, automatically.

What a notified body or authority asks to see: Signed update packages and verification on install; Update server security controls; Rollback protection design
Where lists usually fall short: Updates delivered over unauthenticated channels
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex I Part II(8)Dissemination of security updates without delay and free of charge, with advisories

Where security updates are available for identified issues, manufacturers must disseminate them without delay and, unless otherwise agreed with a business user for a tailor-made product, free of charge, with advisory messages giving users relevant information, including action they may need to take.

What a notified body or authority asks to see: Update release records with advisory messages; Pricing policy showing security updates are free
Where lists usually fall short: Security updates bundled into paid maintenance plans
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex II 2User information: vulnerability contact point and CVD policy location

It must give the single point of contact where vulnerability information can be reported and received, and where the manufacturer's coordinated vulnerability disclosure policy can be found.

What a notified body or authority asks to see: Documentation section naming the vulnerability contact and CVD policy URL
Where lists usually fall short: CVD policy URL broken or not given
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex II 7User information: type of support and end date of the support period

It must state the type of technical security support offered and the end date of the support period during which users can expect vulnerabilities to be handled and security updates to be received.

What a notified body or authority asks to see: Support statement with end date in the documentation
Where lists usually fall short: End date stated as a duration from an unknown start
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex VII 4Technical file: information used to set the support period

It must contain the relevant information taken into account to determine the support period under Article 13(8).

What a notified body or authority asks to see: Support period rationale in the file
Where lists usually fall short: Support period stated with no rationale
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex VIII Part IModule A: internal control

Under internal control the manufacturer draws up the Annex VII technical documentation, takes all measures so that design, development, production and vulnerability handling and their monitoring ensure compliance with Annex I Parts I and II, affixes the CE marking to each conforming product, and draws up the declaration, keeping it with the technical documentation for ten years or the support period if longer. The authorised representative may handle marking and declaration under mandate.

What a notified body or authority asks to see: Internal control file: technical documentation, production and vulnerability handling monitoring records, declaration
Where lists usually fall short: Internal control treated as paperwork with no monitoring of processes
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Annex VIII Part IIModule B: EU-type examination application and manufacturer duties

For EU-type examination the manufacturer applies to a single notified body of its choice, declaring no parallel application, and supplies the technical documentation with an adequate risk analysis and supporting evidence including test results. It must tell the notified body of any modification to the approved type or vulnerability handling processes that may affect conformity (needing an addition to the certificate), accept periodic audits of vulnerability handling, and keep the certificate with the technical documentation for ten years or the support period if longer.

What a notified body or authority asks to see: Application to the notified body with the no-parallel-application declaration; EU-type examination certificate and additions; Records of modifications notified to the body
Where lists usually fall short: Type modified after certification without notifying the body
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 6Condition for making a product available on the market

A product with digital elements may be made available on the Union market only if, when properly installed, maintained and used as intended or under reasonably foreseeable conditions and with the necessary security updates applied, it meets the Part I essential cybersecurity requirements of Annex I, and only if the processes the manufacturer runs meet the Part II vulnerability handling requirements.

What a notified body or authority asks to see: Product-level compliance statement against Annex I Part I; Evidence the Part II vulnerability handling process is operating before release; Release gate record showing both conditions checked
Where lists usually fall short: Product shipped on the strength of product testing alone, with no working vulnerability handling process behind it
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 7(1)Classifying a product as important (Annex III, class I or II)

A product whose core functionality matches a category listed in Annex III is an important product and must follow the stricter conformity routes in Article 32(2) (class I) or 32(3) (class II). Integrating such a component does not by itself move the host product into those routes; the test is the core functionality of the product being placed on the market.

What a notified body or authority asks to see: Classification memo mapping the product's core functionality to Annex III or stating none applies; Reasoning for integrated components that match a category but are not the host product's core function; Record of the conformity route chosen as a result
Where lists usually fall short: Classification made on marketing features rather than core functionality; No review of the classification when the Commission's technical descriptions of the categories are adopted
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 8(1)Critical products and European cybersecurity certification

For products whose core functionality matches an Annex IV category, the Commission may require by delegated act a European cybersecurity certificate at assurance level at least substantial under a scheme adopted under Regulation (EU) 2019/881. Until such an act applies, a critical product must use one of the third-party routes of Article 32(3). The delegated act gives at least six months of transition.

What a notified body or authority asks to see: Determination whether the product falls in Annex IV; Tracking of delegated acts naming a required EUCC or other scheme and assurance level; Plan for certification or for the Article 32(3) route in the meantime
Where lists usually fall short: Critical product treated as class II with no watch on the certification delegated act
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(1)Design, development and production to Annex I Part I

When placing a product on the market the manufacturer must be able to show that it was designed, developed and produced in line with the essential cybersecurity requirements in Part I of Annex I.

What a notified body or authority asks to see: Secure development lifecycle procedure referencing Annex I Part I; Traceability from each applicable Part I requirement to design and test evidence; Release approval showing Part I compliance was checked
Where lists usually fall short: Security requirements added at the end of development rather than designed in; No traceability from requirement to test
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(2)Cybersecurity risk assessment used across the product lifecycle

The manufacturer must assess the cybersecurity risks of the product and feed the outcome into planning, design, development, production, delivery and maintenance, aiming to minimise risk, prevent incidents and reduce their impact, including on users' health and safety.

What a notified body or authority asks to see: Product cybersecurity risk assessment; Evidence that design decisions and backlog items trace to identified risks; Maintenance plan informed by the assessment
Where lists usually fall short: Risk assessment written once for certification and never used by engineering; Health and safety impact of security failures not considered
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(8) first subparagraphEffective vulnerability handling for the support period

From placing on the market and throughout the support period, the manufacturer must make sure that vulnerabilities in the product and its components are handled effectively and in line with the Part II requirements of Annex I.

What a notified body or authority asks to see: Vulnerability handling procedure covering the full support period; Metrics on time to triage and remediate; Evidence of handling for components as well as own code
Where lists usually fall short: Vulnerability handling resourced only for the current release; Components excluded from the process
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(8) second subparagraphDetermining the support period

The manufacturer sets the support period to reflect how long the product is expected to be in use, weighing reasonable user expectations, the nature and intended purpose of the product and relevant Union law on product lifetime. It may also weigh comparable products' support periods, the availability of the operating environment, support periods of key third-party components, and ADCO and Commission guidance. The information used must be recorded in the technical documentation (Annex VII point 4).

What a notified body or authority asks to see: Support period determination memo listing the factors considered; Evidence on expected use time (field data, comparable products); Annex VII point 4 entry in the technical file
Where lists usually fall short: Support period set by commercial preference with no documented reasoning; Third-party component end-of-life dates ignored
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(8) sixth subparagraphPolicies and procedures for reported vulnerabilities, including coordinated disclosure

The manufacturer must have appropriate policies and procedures, coordinated vulnerability disclosure policies among them, to process and remediate potential vulnerabilities reported from inside or outside the organisation.

What a notified body or authority asks to see: Published coordinated vulnerability disclosure policy; Intake and triage procedure for internal and external reports; Records of reports received and their outcome
Where lists usually fall short: Disclosure policy exists but no process sits behind it; Internal findings handled outside the procedure
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(8) third subparagraphMinimum support period of five years

The support period must be at least five years, unless the product is expected to be in use for less than five years, in which case it matches the expected use time. The Commission may set minimum support periods for specific product categories by delegated act where market surveillance data shows periods are inadequate.

What a notified body or authority asks to see: Declared support period of five years or more, or evidence that expected use time is shorter; Watch on category-specific minimums set by delegated act
Where lists usually fall short: Short support period claimed without evidence of short expected use
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(9)Security updates kept available for ten years

Each security update issued to users during the support period must remain available for at least ten years after issue, or for the rest of the support period if that is longer.

What a notified body or authority asks to see: Update archive or distribution service with retention settings; Retention policy stating the ten-year or support-period rule; Spot check that older updates can still be retrieved
Where lists usually fall short: Old update packages deleted when a new version ships; Update server tied to a contract shorter than the retention period
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(12) second subparagraphCarrying out the conformity assessment procedure

The manufacturer must carry out, or have carried out, the conformity assessment procedure it has chosen from those in Article 32 for the product's class.

What a notified body or authority asks to see: Conformity assessment record (internal control report, EU-type examination certificate or quality system approval); Rationale for the chosen procedure
Where lists usually fall short: Internal control used for a product whose class requires a notified body
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(12) third subparagraphEU declaration of conformity and CE marking after demonstrated conformity

Once the conformity assessment has shown that the product meets Annex I Part I and the manufacturer's processes meet Part II, the manufacturer must draw up the EU declaration of conformity under Article 28 and affix the CE marking under Article 30.

What a notified body or authority asks to see: Signed EU declaration of conformity; Evidence of CE marking on product, packaging, declaration or software website as applicable
Where lists usually fall short: CE marking applied before the assessment concluded
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(17)Single point of contact for users

The manufacturer must designate a single point of contact through which users can communicate directly and quickly, including to report vulnerabilities. It must be easy to identify, appear in the Annex II information, let users choose their preferred means of communication and not be limited to automated tools.

What a notified body or authority asks to see: Named single point of contact published in user information; Evidence that at least one non-automated channel is offered; Contact point monitoring and response records
Where lists usually fall short: Contact routed only to a chatbot; Security reports sent to a general support queue with no triage
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 13(19)End date of the support period stated at purchase, and end-of-support notice

The end date of the support period, at least month and year, must be stated clearly at the time of purchase in an easily accessible way and, where applicable, on the product, packaging or by digital means. Where technically feasible, users must be shown a notification when the product reaches the end of its support period.

What a notified body or authority asks to see: Point-of-sale and packaging text showing the end-of-support month and year; In-product or app notification design for end of support
Where lists usually fall short: Support end date published only in a terms page nobody sees before purchase
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 14(1)Notifying actively exploited vulnerabilities to the CSIRT and ENISA

A manufacturer that becomes aware of an actively exploited vulnerability in its product must notify it at the same time to the CSIRT designated as coordinator and to ENISA, through the single reporting platform of Article 16. Applies from 11 September 2026, including to products placed on the market before 11 December 2027 (Article 69(3)).

What a notified body or authority asks to see: Procedure defining 'actively exploited' against the Article 3 definition and who decides; Single reporting platform account and credentials held by named staff; Log of exploited-vulnerability notifications
Where lists usually fall short: No criteria for when reliable evidence of exploitation starts the clock; Reporting owned by nobody outside office hours
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 14(2)(a)Early warning within 24 hours of awareness of an exploited vulnerability

An early warning of the actively exploited vulnerability must go in without undue delay and within 24 hours of the manufacturer becoming aware of it, naming, where applicable, the Member States where the manufacturer knows the product has been made available.

What a notified body or authority asks to see: Awareness timestamp recorded per case; Early warning submissions with time stamps showing the 24-hour limit met; List of Member States of availability kept current for each product
Where lists usually fall short: Awareness time not recorded, so the 24 hours cannot be evidenced; No sales footprint data to name Member States
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 14(2)(b)Vulnerability notification within 72 hours

Unless already provided, a vulnerability notification must follow without undue delay and within 72 hours of awareness, giving available general information on the product, the general nature of the exploit and vulnerability, corrective or mitigating measures taken and those users can take, and, where applicable, how sensitive the manufacturer considers the information.

What a notified body or authority asks to see: 72-hour notification template with the required fields; Submitted notifications with time stamps; Sensitivity marking rationale where used
Where lists usually fall short: User-side mitigations left out of the notification; Sensitivity flag never considered, so delayed dissemination cannot be requested
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 14(3)Notifying severe incidents affecting product security

A manufacturer that becomes aware of a severe incident with an impact on the security of its product must notify it at the same time to the coordinating CSIRT and ENISA via the single reporting platform. An incident is severe where it harms or can harm the product's ability to protect the availability, authenticity, integrity or confidentiality of sensitive or important data or functions, or has led or can lead to malicious code being introduced or run in the product or in users' systems (Article 14(5)).

What a notified body or authority asks to see: Incident classification procedure applying the two Article 14(5) severity tests; Incident register showing classification decisions; Notifications for incidents classed severe
Where lists usually fall short: Incidents in build or update infrastructure not recognised as affecting product security; Severity judged by business impact instead of the Article 14(5) tests
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 14(8)Informing impacted users of exploited vulnerabilities and severe incidents

After becoming aware of an actively exploited vulnerability or severe incident, the manufacturer must inform impacted users, and all users where appropriate, and where needed tell them of risk mitigation and corrective measures they can deploy, where appropriate in a structured, machine-readable format. If the manufacturer does not inform users in time, the notified CSIRTs may do so.

What a notified body or authority asks to see: User notification procedure and templates; Records of advisories sent for each case; Machine-readable advisory format (for example CSAF) where appropriate
Where lists usually fall short: Users informed only through a general release note; No means to reach users of products sold through distributors
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 18(1)-(2)Written mandate for an authorised representative, and what it cannot cover

A manufacturer may appoint an authorised representative by written mandate. The mandate cannot include the Article 13(1) to (11) duties, the drawing up of technical documentation in 13(12) first subparagraph, or the series production duty in 13(14); those stay with the manufacturer.

What a notified body or authority asks to see: Signed written mandate; Mapping of retained manufacturer duties versus delegated tasks
Where lists usually fall short: Mandate purports to hand design or vulnerability handling duties to the representative
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 18(3)Tasks of the authorised representative

The authorised representative performs the mandated tasks and gives the mandate to authorities on request. The mandate must at least let it keep the declaration and technical documentation available for ten years or the support period if longer, provide authorities with conformity information on a reasoned request, and cooperate with them on risk elimination.

What a notified body or authority asks to see: Mandate clauses covering the three minimum tasks; Representative's access to the technical file and declaration; Log of authority requests handled
Where lists usually fall short: Representative holds no copy of the technical file
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 19(1)Importers place only conforming products on the market

Importers may place on the market only products that meet Annex I Part I and whose manufacturer's processes meet Annex I Part II.

What a notified body or authority asks to see: Importer product approval procedure referencing both Parts of Annex I
Where lists usually fall short: Importer checks product paperwork but not the manufacturer's vulnerability handling
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 19(2)Importer checks before placing on the market

Before placing the product, the importer must ensure the manufacturer carried out the right conformity assessment, drew up the technical documentation, applied the CE marking, supplied the EU declaration and the Annex II information in an understandable language, and met the identification, contact and support-end-date duties of Article 13(15), (16) and (19). The importer must be able to produce documents proving these checks.

What a notified body or authority asks to see: Pre-market checklist per product covering points (a) to (d); Copies of conformity assessment evidence and declaration obtained from the manufacturer
Where lists usually fall short: Support end date not checked; Checks done but no documents kept to prove them
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 19(6)Importer retention of the declaration and access to technical documentation

For ten years after placing on the market or the support period if longer, importers must keep a copy of the EU declaration available to authorities and ensure the technical documentation can be made available on request.

What a notified body or authority asks to see: Declaration archive; Contractual commitment from the manufacturer to provide the technical file on request
Where lists usually fall short: No contractual route to obtain the technical file after the supply relationship ends
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 20(1)Distributors act with due care

When making a product available, distributors must act with due care in relation to the Regulation's requirements.

What a notified body or authority asks to see: Distributor compliance procedure for products with digital elements
Where lists usually fall short: Distributor assumes all responsibility sits with the manufacturer
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 20(2)Distributor verification before making available

Before making the product available, distributors must verify that it bears the CE marking and that the manufacturer and importer have met the identification, contact, user information, support end date and declaration duties of Article 13(15), (16), (18), (19) and (20) and Article 19(4), and supplied the necessary documents.

What a notified body or authority asks to see: Goods-in verification checklist; Sample verification records per product line
Where lists usually fall short: Support end date and user information not checked at intake
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 21Importers and distributors who become manufacturers

An importer or distributor is treated as the manufacturer, and takes on Articles 13 and 14, where it places a product on the market under its own name or trademark or carries out a substantial modification of a product already on the market.

What a notified body or authority asks to see: Review of own-brand and modified products to identify where manufacturer duties apply; Manufacturer compliance file for those products
Where lists usually fall short: White-label products sold under own brand with no manufacturer compliance programme
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 28(1)-(2)Drawing up and maintaining the EU declaration of conformity

The manufacturer draws up the EU declaration of conformity stating that the applicable Annex I requirements have been shown to be met. It follows the Annex V model structure, contains the elements required by the Annex VIII procedure used, is updated as appropriate and is provided in the languages required by each Member State where the product is placed or made available. A simplified declaration follows Annex VI. By drawing up the declaration the manufacturer takes responsibility for compliance.

What a notified body or authority asks to see: Current declaration following the Annex V structure; Language versions for each Member State of sale; Version history of the declaration
Where lists usually fall short: Declaration not updated after a new version or changed standard; Missing language versions
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 30(1)-(2)Affixing the CE marking

The CE marking, subject to the general principles of Article 30 of Regulation (EC) No 765/2008, must be affixed visibly, legibly and indelibly to the product; where the product's nature does not allow it, to the packaging and the accompanying declaration. For software, it goes on the declaration or on the accompanying website, in a section directly accessible to consumers. It may be smaller than 5 mm if still visible and legible.

What a notified body or authority asks to see: Marking specification and artwork; Screenshot of the software product web page carrying the marking
Where lists usually fall short: Software marking hidden deep in a legal page
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 31(1)Content of the technical documentation

The technical documentation must contain all relevant data or details of the means used to make the product and the manufacturer's processes meet Annex I, and at least the elements of Annex VII.

What a notified body or authority asks to see: Technical file with an index against Annex VII points 1 to 8
Where lists usually fall short: File describes the product but not the vulnerability handling processes
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 31(2)Technical documentation kept current through the support period

The technical documentation is drawn up before placing on the market and updated continuously, where appropriate, at least through the support period.

What a notified body or authority asks to see: Document control showing revisions tied to releases and vulnerability fixes
Where lists usually fall short: Technical file frozen at first release
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 32(1)Choosing a conformity assessment procedure (default products)

The manufacturer must assess the product and its processes against Annex I and demonstrate conformity by one of: internal control (module A), EU-type examination (module B) followed by conformity to type (module C), full quality assurance (module H), or, where available, a European cybersecurity certification scheme under Article 27(9).

What a notified body or authority asks to see: Conformity assessment plan naming the procedure; Completed module records
Where lists usually fall short: Procedure chosen without first confirming the product is not in Annex III or IV
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 32(2)Conformity assessment for important class I products

For an Annex III class I product, internal control is available only where the manufacturer has applied in full harmonised standards, common specifications or a certification scheme at assurance level at least substantial. Where it has applied them in part, not at all, or none exist, the product and processes must go, for the uncovered requirements, through module B plus C or module H.

What a notified body or authority asks to see: Record of which harmonised standards were applied and whether in full; Notified body certificate where standards were not fully applied
Where lists usually fall short: Internal control used for a class I product while harmonised standards were only partly applied
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 32(3)Conformity assessment for important class II products

For an Annex III class II product, conformity must be shown by module B plus C, module H, or, where available, a European cybersecurity certification scheme at assurance level at least substantial. Internal control is not available.

What a notified body or authority asks to see: EU-type examination certificate, quality system approval or European cybersecurity certificate
Where lists usually fall short: Class II product self-assessed
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)
CRA Art. 32(4)Conformity assessment for critical products

A critical product in Annex IV must show conformity through a European cybersecurity certification scheme required under Article 8(1), or, where those conditions are not met, through one of the Article 32(3) procedures.

What a notified body or authority asks to see: European cybersecurity certificate at the required assurance level, or third-party procedure record
Where lists usually fall short: Certification route assumed available before the delegated act applies
Source: EU Cyber Resilience Act (Regulation (EU) 2024/2847)