ciso.diy
CRA Manufacturer Set preview
Bundles Cyber Resilience ActCRACE markingSBOM

CRA Manufacturer Set

The whole CRA line in one purchase — scope the obligation, run the Article 14 clock that is already live, and produce the technical file, SBOM and CE declaration for December 2027. 19% off buying the three separately.

What this actually gives you

  • Three different jobs, usually three different people — the governance owner scoping the obligation, the PSIRT running the Article 14 clock at 2 a.m., and the product lead handing a notified body the technical file.
  • Article 14 reporting starts 11 September 2026 — the first part of the CRA that binds, and the one with hours rather than months on it. Everything else lands 11 December 2027.
  • The date that actually binds is earlier than 2027. With harmonised standards late and notified-body capacity the bottleneck, the route decision’s start-by date falls well inside 2026 for most manufacturers.

Everything a manufacturer under the Cyber Resilience Act has to do, and the three products that do it.

EU Cyber Resilience Act Workbook — the scope test that tells you whether the regulation attaches to you at all, the Annex I essential requirements mapped against controls you may already have, conformity assessment routes, the vulnerability handling process, and the dated road to December 2027. The governance owner's half.

CRA 24-Hour Reporting Clock — starting 11 September 2026, and therefore the first part of the CRA you can be late on today. The actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA notification drafts, the PSIRT/CSIRT RACI, and a coordinated disclosure policy you publish under your own name.

CRA Conformity Package — the artefacts themselves, for 11 December 2027: the product classifier, the Annex I checklist, the conformity route decision with its notified-body lead times, the Annex VII technical documentation template, the SBOM and VEX pack with a CycloneDX template, the support-period statement and the Annex V declaration.

Why all three. They are three different jobs and usually three different people. The workbook decides whether the obligation attaches and what it costs; the clock is what the PSIRT runs at 2 a.m. when a vulnerability in your product is being exploited; the package is what the product lead hands a notified body, a customer or a market-surveillance authority. Owning the middle one without the third leaves you reporting incidents on a product you cannot lawfully sell after December 2027; owning the third without the second leaves you CE-marked and silent on the one clock that is already running.

The date that actually binds is earlier than 2027. A Class I product with no listed harmonised standard has no self-assessment route, and notified-body capacity is the bottleneck — the conformity route decision computes the start-by date, which for most manufacturers falls well inside 2026.

What's included

  • PDF — fully editable
  • Complete Library (.zip) — all formats included — fully editable
  • Instant download after purchase
  • Free updates — re-download when we release new versions
One-time purchase
$358.00
  • Secure checkout via Stripe
  • All major cards accepted
  • 30-day satisfaction guarantee
Version 1.0
Last updated 2026-09-08