ciso.diy
CRA Conformity Package preview
Compliance Cyber Resilience ActCRACE markingtechnical documentation

CRA Conformity Package

Full CRA applies 11 December 2027 — the technical file, the SBOM and the CE declaration, ready to fill. Classify by core function, meet Annex I, choose the route, build the Annex VII file, ship the SBOM, declare the support period, sign the Annex V declaration.

What this actually gives you

  • Article 14 reporting starts 11 September 2026 — days away, and the first part of the CRA you can be late on. Everything else — classification, Annex I, conformity, the technical file, the declaration and CE — applies 11 December 2027.
  • Harmonised standards are late. The Annex I property standard is not expected before late 2027, so a Class I product without a listed standard has no self-assessment route and needs a notified body.
  • Class II and critical products need a notified body regardless — and notified-body capacity is the 2027 bottleneck. The lead time on that engagement, not the paperwork, decides whether you make the date.
  • Classification is by core function, not feature list. A laptop that merely includes a fingerprint reader is not thereby an important product; a smart TV that merely includes a browser is not thereby Class I.

Article 14 reporting starts on 11 September 2026. Everything else lands on 11 December 2027 — classification, Annex I, conformity assessment, the technical file, the declaration and the CE mark. This is the kit for that second date: not the obligations map, but the documents themselves.

The standards are late, and that is the whole planning problem. The Annex I property standard is not expected before late 2027. A Class I product without a listed harmonised standard has no self-assessment route — it needs a notified body. Class II and critical products need one regardless, and notified-body capacity is the 2027 bottleneck. The lead time on that engagement, not the paperwork, is what decides whether you make the date.

Classification is by core function, not feature list. The Commission's April 2026 technical descriptions settled it: a laptop that merely includes a fingerprint reader is not thereby an important product, and a smart TV that merely includes a browser is not thereby a Class I one. Files 01 and 08 work the "merely includes" test through both examples.

What you get

01 Product Classifier + Portfolio (XLSX) — thirteen questions per product return scope, class (default / Class I / Class II / critical), route, whether a notified body is required, the documentation form, the support period, live reporting duties and role duties. The portfolio roll-up counts your notified-body engagements and, critically, your standard-less Class I products.

02 Annex I Requirements Checklist (XLSX) — Part I essential properties (a) to (m), Part II vulnerability handling (1) to (8), and the ten Annex II user-information items, each with applies / status / evidence / standard clause. Its summary decides one thing: whether a declaration is possible yet.

03 Conformity Route Decision (XLSX) — class, standards, QMS and variants in; permitted procedures, recommended module (A, B+C, H or EUCC), notified-body need, presumption of conformity, standards watch, lead time and a start-by date out. With the modules explained and a notified-body selection tracker.

04 Technical Documentation Template (DOCX) — Annex VII in its own order: description, design, production and vulnerability handling, risk assessment, requirements and demonstration of conformity, test reports, declaration, SBOM and additional elements.

05 SBOM/VEX Pack (XLSX + CycloneDX JSON) — a human-readable SBOM register, VEX statements with justifications and an Article 14 trigger column, the SBOM process itself, and a minimal CycloneDX 1.6 template with a vulnerability block.

06 Support-Period & Vulnerability-Handling Statement (DOCX) — the public support-period statement Article 13(8) requires, the Annex I Part II commitments, the end-of-support plan and the internal decision record behind the number you publish.

07 EU Declaration of Conformity (DOCX) — the Annex V model in full, the Annex VI simplified declaration, and a pre-signature checklist covering CE marking and labelling.

08 Practitioner Guide (PDF) — where the CRA stands, roles, classification by core function, Annex I, routes and the standards problem, notified bodies, the technical file, SBOM and VEX, the support period, declaration and CE, substantial modification, sequencing, failure patterns and an FAQ.

cra03.json — classes, routes, Annex I references and timelines, machine-readable.

Annex numbering follows the adopted text. I is the essential requirements (Parts I and II), II user information, III important products (Class I and II), IV critical, V the declaration, VI the simplified declaration, VII technical documentation, VIII procedures. One Commission summary page numbers the technical-documentation annex VI; the adopted text says VII, and this kit follows the text.

Where it sits in the line. The EU Cyber Resilience Act Workbook scopes the obligation and maps it — that is the governance owner's job. The CRA 24-Hour Reporting Clock runs Article 14, which starts 11 September 2026 — that is the PSIRT's. This is the product lead's: the artefacts a notified body, a customer or a market-surveillance authority actually asks to see. Supplier SBOMs and component assurance run through the Vendor Risk Operations Kit and the TPRM Program Kit; the Security Metrics & KPI Library carries the SBOM-coverage and disclosure-intake measures.

Harmonised-standard citations and their timeline are marked "verify final" throughout, as is the Annex III/IV category wording pending any delegated act. Files 06 §1 and 07 are documents you publish under your own name — they ship with the ciso.diy footer and you strip it on publication, the same convention the CRA-02 disclosure policy uses.

A practitioner's toolset, not legal advice. The declaration in file 07 carries legal liability for the signer, and the support-period commitment in file 06 is a promise to your market — have counsel, and where required a notified body, review both before you sign or publish.

What's included

  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
  • Practitioner License: unlimited client use (vCISO / MSP)

Choose your license:

  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-04
Pages 8