Standard Operating Procedures
These procedures are step-by-step instructions for getting a job done, distinct from the reference pages elsewhere in these docs, which describe what each screen is. Each one states its audience, the outcome it produces, its prerequisites and a completion checklist, and ties every step to the CRA obligation it satisfies.
| Procedure | Audience | Covers |
|---|---|---|
| SOP-01, Setting Up Your CVD Portal | Manufacturer, first-time setup | Registration through to a verified public portal, published security.txt, and a recording audit log |
| SOP-02, Taking a Product Through CRA Compliance | Manufacturer, per product | Classification, Article 32 route, risk assessment, the 22 Annex I requirements, technical file, monitoring clock |
| SOP-03, Onboarding a Client and Running Their CRA Compliance | Consultancy or reseller | Client workspace creation, billing, consultant seat, running a client's product, bulk intake, review queue |
| SOP-04, Filing an Article 14 Report | Whoever is on call during an incident | The 24h early warning, 72h notification and final report, from classification through to recording the ENISA SRP reference |
| SOP-05, Triaging a Vulnerability Report | Whoever works the inbox daily | Acknowledge, score, assign, establish affected components, coordinate upstream, record the remediation decision |
| SOP-06, Knowing Whether an Upstream Vulnerability Affects You | Whoever owns the component inventory | SBOM upload, version-exact OSV matching, vendor watchlist, supplier due diligence, CI findings |
| SOP-07, Producing the Auditor Evidence Package | Whoever faces an auditor or a questionnaire | Working the obligations tracker, then exporting the dated evidence package |
| SOP-08, Enterprise Account Administration | Account administrator, once at rollout | SSO, API keys, webhooks, trust portal, EUDI identity, security review plan |
SOP-04 is the one to read before it is needed. It is time-boxed by statute, and it leads with the fact that trips people up: the portal prepares the package and records the filing, but the manufacturer submits it to ENISA themselves.
SOP-08 is a bundle of independent tasks rather than a sequence. The rest are ordered procedures.
How they connect
SOP-01 gets reports arriving. SOP-05 is what happens to each one after it lands, and hands off to SOP-04 the moment a report is classified as actively exploited or a severe incident. SOP-02 runs a product through conformity; SOP-06 keeps the component inventory underneath it honest. SOP-07 is the paperwork that proves any of it happened. SOP-03 is the consultancy view of SOP-01, SOP-02 and SOP-05 performed on someone else's tenant.
About the screenshots
Screenshots are taken from a populated demonstration workspace. Figures, company names, product names and counts are illustrative. Every generated conformity document is a draft with placeholders and is not fit for issuance without review; each procedure says so explicitly where it applies.