CRA compliance features
CRA compliance in CVD Portal guides manufacturers through Cyber Resilience Act requirements as a single ordered path.
Ordered compliance workflow
Each product follows an ordered sequence of readiness checks:
- Classify the product: Determine the Annex III/IV category and Article 32 conformity route.
- Record the notified body: Required when self-assessment under Module A is unavailable.
- Describe the product: Provide Clause 6.2 context inputs.
- Record the risk registers: Confirm at least one asset, record at least one threat of your own, and record at least one risk. Required once the risk assessment documents carry content.
- Assess the risk: Score the risks and determine treatment.
- Sign off the requirements: Complete the Annex I essential requirements checklist.
- Attach the evidence: Attach audit-ready evidence to applicable controls.
- Upload the SBOM: Provide the Software Bill of Materials (Annex VII point 8).
The product header displays the current step as the primary action. Subsequent steps remain available through progressive disclosure sections that show their current status.
Workspace components
- Products workspace: Product classification, risk assessment, Annex I checklist, technical file artifacts, and conformity documentation.
- Article 14 reporting: 24-hour early warning, 72-hour notification, and final incident reporting.
- SBOM registry: Software Bill of Materials tracking and vulnerability monitoring.
- Upstream reporting: Third-party and open-source component duties.
- Feature guide: Platform-wide capabilities overview.