CRA Governance + Reporting
EU Cyber Resilience Act Workbook + CRA 24-Hour Reporting Clock — the governance half and the operational half of the CRA in one purchase. 14% off buying them separately. For the conformity artefacts as well, see the CRA Manufacturer Set.
What this actually gives you
- The workbook tells you whether the obligation attaches and what you must build. The clock tells you what to do in the twenty-four hours after someone exploits your product.
- Buying only the first leaves you compliant on paper and improvising on the day; buying only the second leaves you with a runbook and no idea whether you are in scope.
The Cyber Resilience Act split into the two halves it actually has: the governance work that runs to December 2027, and the reporting clock that starts on 11 September 2026.
EU Cyber Resilience Act Workbook — the scope test that tells you whether you are a manufacturer under the regulation, the Annex I essential requirements mapped to controls you may already have, the Annex VII technical documentation set, conformity assessment routes and where a notified body is required, the vulnerability handling process, the support-period declaration, and the dated road to December 2027.
CRA 24-Hour Reporting Clock — the operational half. The actively-exploited evidence test, the 24/72/14-day sequencer, the four-regime harmonization matrix against NIS2, DORA and GDPR, field-complete ENISA notification drafts, the PSIRT/CSIRT RACI, and a coordinated vulnerability disclosure policy you can publish under your own name.
Why both. The workbook tells you whether the obligation attaches and what you must build. The clock tells you what to do in the twenty-four hours after someone exploits your product. Buying only the first leaves you compliant on paper and improvising on the day; buying only the second leaves you with a runbook and no idea whether you are in scope.
Delivered as two separate downloads — the workbook as PDF, the clock pack as a ZIP of seven deliverables.
This is two of the three CRA products. If you also have to produce the technical file, the SBOM and the CE declaration for December 2027, the CRA Manufacturer Set adds the CRA Conformity Package to these two.
What's in this bundle
EU Cyber Resilience Act Workbook
Article 14 reporting readiness and the road to December 2027 — the scope test, the reporting clocks, Annex I requirements mapped to controls, the technical documentation set, and conformity assessment routes. Neither DORA nor NIS2 covers this.
CRA 24-Hour Reporting Clock
The clock starts 11 September 2026. The runbook for the 24 hours after you learn a vulnerability in your product is being exploited — the actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA notification drafts, the PSIRT/CSIRT RACI, and a CVD policy you can publish as-is.
What's included
- PDF — fully editable
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
More from the CISO Marketplace ecosystem
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee