Product Security Complete
Everything a product vendor owes the EU and the crypto clock in one purchase — the CRA scope test, the Article 14 reporting runbook, the technical file with SBOM and CE declaration, and the post-quantum inventory and migration plan. 19% off buying the four separately.
What this actually gives you
- A product you CE-mark in 2027 with a ten-year support commitment is one you have promised to keep cryptographically current into the 2030s — which is why the SBOM and the crypto inventory belong in the same purchase.
- Article 14 reporting starts 11 September 2026; full CRA applies 11 December 2027; NIST deprecates RSA-2048 and P-256 after 2030.
- Sold as a Standard licence because two of the four components are sold that way — buy the conformity or post-quantum kits directly if you need Organization or MSSP scope.
If you ship a product with digital elements into the EU, three deadlines are already moving and a fourth is arriving underneath all of them.
EU Cyber Resilience Act Workbook — whether the regulation attaches to you at all, the Annex I essential requirements mapped against controls you may already have, the conformity routes, and the dated road to December 2027.
CRA 24-Hour Reporting Clock — starting 11 September 2026, so the first part of this set that binds. The actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA drafts and a coordinated disclosure policy you publish under your own name.
CRA Conformity Package — for 11 December 2027: the product classifier, the Annex I checklist, the conformity route decision with notified-body lead times, the Annex VII technical documentation template, the SBOM and VEX pack, the support-period statement and the Annex V declaration.
Post-Quantum Migration Kit — the cryptography underneath all of it. One row per cryptographic use, the Mosca check that says whether you are already late, four migration waves, a vendor questionnaire with hard stops, and the deadline calendar from EO 14412 through CNSA 2.0 to 2035.
Why the fourth one belongs here. The CRA's Annex I asks you to protect confidentiality and integrity with state-of-the-art mechanisms and to ship an SBOM. EO 14412 commissioned a CBOM standard, NIST deprecates RSA-2048 and P-256 after 2030, and your support period almost certainly runs past that date. A product you CE-mark in 2027 with a ten-year support commitment is a product you have promised to keep cryptographically current into the 2030s — so the bill of materials and the crypto inventory are the same exercise done twice unless you do them together.
Sold as a Standard licence because two of the four components are sold that way. If you need Organization or vCISO/MSSP scope on the conformity or post-quantum kits, buy those directly.
What's in this bundle
EU Cyber Resilience Act Workbook
Article 14 reporting readiness and the road to December 2027 — the scope test, the reporting clocks, Annex I requirements mapped to controls, the technical documentation set, and conformity assessment routes. Neither DORA nor NIS2 covers this.
CRA 24-Hour Reporting Clock
The clock starts 11 September 2026. The runbook for the 24 hours after you learn a vulnerability in your product is being exploited — the actively-exploited evidence test, the 24/72/14-day sequencer, field-complete ENISA notification drafts, the PSIRT/CSIRT RACI, and a CVD policy you can publish as-is.
CRA Conformity Package
Full CRA applies 11 December 2027 — the technical file, the SBOM and the CE declaration, ready to fill. Classify by core function, meet Annex I, choose the route, build the Annex VII file, ship the SBOM, declare the support period, sign the Annex V declaration.
Post-Quantum Migration Kit
The board will ask about quantum. Have the inventory and the plan — one row per cryptographic use, a Mosca check that tells you whether you are already late, four migration waves, a vendor questionnaire with hard stops, and the deadline calendar behind all of it.
What's included
- PDF — fully editable
- Complete Library (.zip) — all formats included — fully editable
- Instant download after purchase
- Free updates — re-download when we release new versions
More from the CISO Marketplace ecosystem
- Secure checkout via Stripe
- All major cards accepted
- 30-day satisfaction guarantee