Skip to main content

Standard Operating Procedures

These procedures are step-by-step instructions for getting a job done, distinct from the reference pages elsewhere in these docs, which describe what each screen is. Each one states its audience, the outcome it produces, its prerequisites and a completion checklist, and ties every step to the CRA obligation it satisfies.

ProcedureAudienceCovers
SOP-01, Setting Up Your CVD PortalManufacturer, first-time setupRegistration through to a verified public portal, published security.txt, and a recording audit log
SOP-02, Taking a Product Through CRA ComplianceManufacturer, per productClassification, Article 32 route, risk assessment, the 22 Annex I requirements, technical file, monitoring clock
SOP-03, Onboarding a Client and Running Their CRA ComplianceConsultancy or resellerClient workspace creation, billing, consultant seat, running a client's product, bulk intake, review queue
SOP-04, Filing an Article 14 ReportWhoever is on call during an incidentThe 24h early warning, 72h notification and final report, from classification through to recording the ENISA SRP reference
SOP-05, Triaging a Vulnerability ReportWhoever works the inbox dailyAcknowledge, score, assign, establish affected components, coordinate upstream, record the remediation decision
SOP-06, Knowing Whether an Upstream Vulnerability Affects YouWhoever owns the component inventorySBOM upload, version-exact OSV matching, vendor watchlist, supplier due diligence, CI findings
SOP-07, Producing the Auditor Evidence PackageWhoever faces an auditor or a questionnaireWorking the obligations tracker, then exporting the dated evidence package
SOP-08, Enterprise Account AdministrationAccount administrator, once at rolloutSSO, API keys, webhooks, trust portal, EUDI identity, security review plan

SOP-04 is the one to read before it is needed. It is time-boxed by statute, and it leads with the fact that trips people up: the portal prepares the package and records the filing, but the manufacturer submits it to ENISA themselves.

SOP-08 is a bundle of independent tasks rather than a sequence. The rest are ordered procedures.

How they connect

SOP-01 gets reports arriving. SOP-05 is what happens to each one after it lands, and hands off to SOP-04 the moment a report is classified as actively exploited or a severe incident. SOP-02 runs a product through conformity; SOP-06 keeps the component inventory underneath it honest. SOP-07 is the paperwork that proves any of it happened. SOP-03 is the consultancy view of SOP-01, SOP-02 and SOP-05 performed on someone else's tenant.

About the screenshots

Screenshots are taken from a populated demonstration workspace. Figures, company names, product names and counts are illustrative. Every generated conformity document is a draft with placeholders and is not fit for issuance without review; each procedure says so explicitly where it applies.