CRA Manufacturer Set
The whole CRA line in one purchase — scope the obligation, run the Article 14 clock that is already live, and produce the technical file, SBOM and CE declaration for December 2027. 19% off buying the three separately.
What this actually gives you
- Three different jobs, usually three different people — the governance owner scoping the obligation, the PSIRT running the Article 14 clock at 2 a.m., and the product lead handing a notified body the technical file.
- Article 14 reporting starts 11 September 2026 — the first part of the CRA that binds, and the one with hours rather than months on it. Everything else lands 11 December 2027.
- The date that actually binds is earlier than 2027. With harmonised standards late and notified-body capacity the bottleneck, the route decision’s start-by date falls well inside 2026 for most manufacturers.
Everything a manufacturer under the Cyber Resilience Act has to do, and the three products that do it.
EU Cyber Resilience Act Workbook — the scope test that tells you whether the regulation attaches to you at all, the Annex I essential requirements mapped against controls you may already have, conformity assessment routes, the vulnerability handling process, and the dated road to December 2027. The governance owner's half.
CRA 24-Hour Reporting Clock — starting 11 September 2026, and therefore the first part of the CRA you can be late on today. The actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA notification drafts, the PSIRT/CSIRT RACI, and a coordinated disclosure policy you publish under your own name.
CRA Conformity Package — the artefacts themselves, for 11 December 2027: the product classifier, the Annex I checklist, the conformity route decision with its notified-body lead times, the Annex VII technical documentation template, the SBOM and VEX pack with a CycloneDX template, the support-period statement and the Annex V declaration.
Why all three. They are three different jobs and usually three different people. The workbook decides whether the obligation attaches and what it costs; the clock is what the PSIRT runs at 2 a.m. when a vulnerability in your product is being exploited; the package is what the product lead hands a notified body, a customer or a market-surveillance authority. Owning the middle one without the third leaves you reporting incidents on a product you cannot lawfully sell after December 2027; owning the third without the second leaves you CE-marked and silent on the one clock that is already running.
The date that actually binds is earlier than 2027. A Class I product with no listed harmonised standard has no self-assessment route, and notified-body capacity is the bottleneck — the conformity route decision computes the start-by date, which for most manufacturers falls well inside 2026.
What's in this bundle
EU Cyber Resilience Act Workbook
Article 14 reporting readiness and the road to December 2027 — the scope test, the reporting clocks, Annex I requirements mapped to controls, the technical documentation set, and conformity assessment routes. Neither DORA nor NIS2 covers this.
CRA 24-Hour Reporting Clock
The clock starts 11 September 2026. The runbook for the 24 hours after you learn a vulnerability in your product is being exploited — the actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA notification drafts, the PSIRT/CSIRT RACI, and a CVD policy you can publish as-is.
CRA Conformity Package
Full CRA applies 11 December 2027 — the technical file, the SBOM and the CE declaration, ready to fill. Classify by core function, meet Annex I, choose the route, build the Annex VII file, ship the SBOM, declare the support period, sign the Annex V declaration.
What's included
- PDF — fully editable
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
More from the CISO Marketplace ecosystem
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee