Skip to main content

Taking a Product Through CRA Compliance

Audience. A manufacturer running one product with digital elements through CRA self-assessment, from classification to a draft Declaration of Conformity.

Outcome. A classified product, a completed Annex I self-assessment with evidence attached, a generated technical file, and a periodic review clock running.

Why it matters. Full CRA obligations apply from 11 December 2027. Products in Annex III Class I or Class II cannot use pure self-assessment, and finding that out late is expensive. Classification is therefore the first step, not a formality.

Time required. Classification and conformity route take under an hour. The full Annex I assessment and evidence collection are a project measured in weeks and involve engineering.

Prerequisites.

  • SOP-01 complete, or at least a verified workspace.
  • The product manual, datasheet or requirements documentation.
  • Someone who can speak to the product architecture, for the risk assessment.

A note on the two sides of the app. The left rail switches between CVD Portal, which handles vulnerability intake, and CRA Portal, which handles product conformity. This SOP works entirely in the CRA Portal side.


Step 1. Open the CRA overview

Switch the rail to CRA Portal and open Overview.

The overview is the status board for everything CRA. It shows products in scope, how many Annex I essential requirements are evidenced, open review items, and reporting readiness against the 11 September 2026 date.

CRA compliance overview

Product conformity readiness lists each product with its classification, technical file progress, essential requirements progress and evidence progress.

Product conformity readiness

Use this panel to decide which product to work. Anything showing "classification undecided" is blocked from being placed on the market and should be handled first.

Step 2. Add the product

Open Products and select Add product.

Products list

Give the product a name and a short functional description, for example "Home internet router with VPN and firewall".

Add product form

Write the description in terms of what the product does, not what it is called internally. The description feeds the classification decision and the drafted artifacts, so a vague description produces vague output.

If you already have a manual or datasheet, Upload a document on the products page extracts product context automatically instead.

Step 3. Read the product workspace

Open the product. The header carries the classification, the conformity route, and three progress counters for technical file artifacts, criteria passed and evidence ready.

Remaining work tells you the current stage and the single next action. Work that prompt rather than guessing where to go next.

Product assessment workspace

The five tabs are the whole process.

  • Assess. Classification, conformity route, product context, risk assessment.
  • Requirements. The 22 Annex I requirements with owners, evidence and sign-off.
  • Evidence. Attached evidence mapped to controls.
  • Conformity. Technical file, Declaration of Conformity, CE marking, user information.
  • Monitoring. Periodic review clock and review triggers.

Step 4. Decide the CRA classification

On the Assess tab, open CRA classification (Annex III / IV).

Select the Annex III or Annex IV category the product falls into, or the default category if it is neither important nor critical.

CRA classification

List the harmonised standards or EUCC certification applied. Quick-add buttons cover the common ones including prEN 40000-1-2, prEN 40000-1-3, ETSI EN 303 645, IEC 62443-4-1, IEC 62443-4-2, ISO/IEC 27001, ISO/IEC 29147 and ISO/IEC 30111.

No harmonised standard is cited in the Official Journal for the CRA yet, so no presumption of conformity is available. What you list here documents your state of the art baseline and prepares the Article 32 route for when citation happens.

Record the Classification basis. This is required for any non-default class before placing on the market under Article 13(4). State the reasoning, not just the conclusion.

Select Save classification.

Get this wrong in the optimistic direction and you will build a Module A self-assessment for a product that legally requires a notified body. Classify honestly against the product's core function.

Step 5. Confirm the conformity route

The Conformity route (Article 32) panel derives the permitted routes from the classification.

Conformity route

For a Class II product the route is Module B plus C, Module H, or an EUCC scheme at assurance level substantial or higher, per Article 32(3). Self-assessment under Module A is not permitted.

This panel is derived, not chosen. If the route is not what you expected, the classification above it is what needs revisiting.

Step 6. Provide product context

Open Product context (Clause 6.2).

Enter the raw product-context facts, or paste a manual into Extract from a manual to auto-fill them. These facts feed every drafted Clause 6 and Clause 7 artifact in the Requirements tab.

Product context

Context quality determines artifact quality. Time spent here is recovered several times over in the Requirements tab.

Step 7. Complete the risk assessment

Work through Risk assessment, covering assets, data-flow diagrams, the STRIDE threat model, remote data processing, and the essential requirements under Annex I Part I(2).

Risk assessment

STRIDE threat model

The risk assessment is what determines which of the 13 Part I(2) product security requirements are applicable to this product. Skipping it leaves every requirement marked applicable and inflates the work in the next step.

Step 8. Work the Annex I checklist

Open the Requirements tab.

This is the self-assessment against all 22 Annex I requirements, being the overarching Part I(1) requirement, the 13 Part I(2) product security requirements, and the 8 Part II vulnerability handling requirements.

Annex I checklist

Requirements tab

For each requirement, assign an owner and a due date, record the evidence, capture sign-off, and note any residual risk. Owners are emailed when an item comes due.

Applicability for the Part I(2) items comes from the risk assessment in Step 7. If something is marked applicable that should not be, fix it in the risk assessment rather than here.

Assign owners early even if evidence is months away. An unassigned requirement has no route to completion.

Step 9. Attach evidence

Open the Evidence tab.

Attach the artifacts that substantiate each control. Confirmed evidence appears here once accepted.

Evidence tab

The Clause artifacts section on the Assess tab covers Clause 6.2 through 7.9 and drafts the documents that make up the technical file.

Clause artifacts

Step 10. Generate the conformity documents

Open the Conformity tab.

Conformity tab

Export approval (four-eyes review). Turn on Require approval before export so the Annex VII export only unlocks after a second admin approves. Any later change to the assessment makes the sign-off stale and requires re-approval.

Conformity documents. Generate the draft EU Declaration of Conformity (Annex V), the simplified declaration for inclusion with the product (Annex VI), and the Annex VII technical documentation index.

These are drafts with placeholders and are explicitly not for issuance. They are a starting point for your legal review, not a substitute for it.

Technical file. Export as print or PDF, or download JSON. The export runs the CRA conformance checks, and a product with open issues cannot be exported.

CE marking. Guidance for affixing the CE marking under Articles 29 and 30, tailored to this product's route.

User information (Annex II). Set the support period in months or as an end date under Article 13(8), save it, then generate the draft user information sheet that must accompany the product.

Step 11. Start the monitoring clock

Open the Monitoring tab.

Monitoring tab

Periodic documentation review. The recurring check that keeps the risk assessment, technical documentation and Declaration of Conformity current under Articles 31(2) and 13(3). The clock starts when you capture the first snapshot under Actions, which marks placing on the market. Cadence follows the risk-review artifact C6.7-OUT-01 unless overridden to quarterly or semi-annual.

Monitoring and review. Record triggers that require re-reviewing the assessment, being a threat landscape change, a cybersecurity issue, or a risk exposure change. A trigger stays open until a documentation review closes it.

Vulnerabilities found in the product do not belong here. Those go through the Article 14 reporting workflow in the CVD Portal side of the app.

Trust portal. Optionally share the product's latest frozen snapshot with approved viewers. Only snapshots are shared, never live drafts.

Step 12. Confirm readiness

Open Readiness and review CRA Product Conformity Readiness.

Product conformity readiness

This is the view to take to a management review. It shows every product against the December 2027 obligations rather than a single product in isolation.


Completion checklist

  • Product created with a functional description
  • Annex III / IV classification decided and saved
  • Classification basis recorded, as required by Article 13(4)
  • Harmonised standards and any EUCC certification listed
  • Conformity route confirmed and understood
  • Product context complete
  • Risk assessment complete, including assets, data flows and threat model
  • All 22 Annex I requirements have an owner
  • Evidence attached and confirmed against controls
  • Four-eyes export approval enabled
  • Draft Declaration of Conformity and Annex VII index generated
  • Support period set and Annex II user information sheet generated
  • Technical file exported with no open issues
  • First snapshot captured and the review clock running

Important limitations

  • Every generated conformity document is a draft with placeholders. None is fit for issuance without legal review.
  • Products in Annex III Class I or Class II require a third-party conformity route. The app prepares the technical file, it does not replace a notified body.
  • No harmonised standard is currently cited in the Official Journal for the CRA, so no presumption of conformity is available to any product yet.