Regulation (EU) 2024/2847 of the European Parliament
Cyber Resilience Act (CRA) Documentation Pack
The CRA’s first deadline is closer than most manufacturers think.
Everyone’s treating the Cyber Resilience Act as a 2027 problem. It isn’t.
From 11 September 2026, if you make a product with digital elements available on the EU market, you must report actively exploited vulnerabilities and severe incidents to ENISA within 24 hours — and that obligation reaches products already on the market, not just new ones.
This pack gives you the five evidence documents the CRA requires, built to the Regulation’s own annexes, with the reporting-readiness document you need first.



5 documents, 58 pages




Who needs this pack:
Built for manufacturers of hardware and software products with digital elements selling into the EU. This documentation pack is also suitable for the importers and own-branders who inherit the manufacturer’s obligations without realising it:
- Hardware and software manufacturers placing connected products on the EU market.
- Importers and distributors who need to verify — or who’ve discovered they’re treated as manufacturers because they own-brand or substantially modify. IoT, industrial, and embedded-systems businesses facing Annex III classification.
- Component suppliers whose customers are demanding CRA evidence up the supply chain.
- Fractional compliance leads and product-security teams who want a defensible, annex-mapped starting point rather than a blank technical file.
What you get:
Five documents, each an Explanatory Notice (the reasoning and the relevant legal text) paired with a ready-to-complete template:
SCOPE — an applicability and product classification assessment. Is your product in scope? Is it default (self-assess), important Class I/II (Annex III), or critical (Annex IV)? Which conformity-assessment route follows — internal control, or a notified body? What’s your support period? This is the entry document, and it’s free to download — see below.
REPORT — Article 14 incident and vulnerability reporting readiness. The 24-hour / 72-hour / 14-day cadence to ENISA’s Single Reporting Platform, with the internal escalation chain that makes a 24-hour deadline achievable. This is the one with a 2026 deadline. Start here.
RECORD — the Annex VII technical documentation file, the ten-year technical file, with a compliance matrix covering all thirteen essential security requirements in Annex I Part I, mapped requirement by requirement to your evidence.
VULN — vulnerability handling and SBOM (Annex I Part II). The eight process obligations, the software bill of materials in machine-readable format (CycloneDX or SPDX), and the coordinated vulnerability disclosure policy.
DOC — the EU Declaration of Conformity (Annex V), the CE marking record (Article 30), and the Annex II information you must give users.
Each document is a draft for legal review, structured so a lawyer can approve it fast and a market surveillance authority — or a notified body — can follow it.
Why this maps to the Regulation, not to a generic checklist
CRA compliance is defined precisely in the annexes, and this pack is built to them.
- Annex VII fixes the eight-point content of your technical file
- Annex I Part I lists the thirteen security properties your product must have. Part II lists the eight vulnerability-handling processes you must run.
- Annex V fixes the Declaration of Conformity
- Annex II the user information
- Annexes III and IV the product classifications that decide whether you self-assess or need a notified body.
Every document here is drafted to a specific annex, with the relevant legal text quoted in each so you can see exactly what’s being satisfied.
CRA deadline is already moving
The reporting obligation applies from 11 September 2026 — fifteen months before the essential requirements, conformity assessment and CE marking apply on 11 December 2027.
Meeting a 24-hour reporting deadline becomes a detection-to-disclosure workflow that has to be designed and rehearsed before an incident, not figured out during one. The REPORT document builds that readiness. It’s the reason this pack earns its place on your desk in 2026, not 2027.
Start with the free document
Download the SCOPE applicability and classification assessment at no cost. Work through it, and you’ll know whether the CRA applies to your product, how it’s classified, which conformity route you face, and which of the five documents you need — before you spend anything.
Download the free scoping document
Who built this pack
Drafted by a qualified lawyer working in EU AI regulation, not assembled from a template library.
Commissioning the equivalent from a law firm is 15 to 40 hours of specialist time. At prevailing rates that is €6,000 to €18,000.
What the price covers
The full Cyber Resilience Act compliance pack — all five documents — is €700, including twelve months of updates as the harmonised standards and Commission guidance land (€300/year thereafter).
The first CRA harmonised standards are expected across 2026–2027 so updates keep your file current as they arrive. Add a lawyer review of your completed documents, or step up to a full product assessment, when you need it.
A specialist firm scoping a CRA technical file and vulnerability-handling programme from scratch will typically run €6,000–18,000 per product line. The pack is the same structure at a fraction of the cost, with the reasoning included so you understand what you’re signing.
What this pack is not (Important)
This is not legal advice, and it’s not filing-ready out of the box. It’s professionally structured evidence documentation that a qualified lawyer and your product-security team should review against your specific product before you rely on it. It takes positions on genuinely unsettled questions — borderline product classification, the open-source-steward carve-out, the support-period floor, and the standards-availability test that decides whether an “important” product needs a notified body — that you will want to review as guidance and harmonised standards mature.
