EU Cyber Resilience Act compliance checklist
Work through the capabilities the Cyber Resilience Act expects, from product classification and the risk assessment through the Declaration of Conformity to the Article 14 reporting deadlines. Your progress is saved in your browser. Email or print the result for your compliance file.
What the CRA requires
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for every product with digital elements placed on the EU market. Article 14 vulnerability and incident reporting applies from 11 September 2026, and the full regulation, including CE marking, applies from 11 December 2027.
Compliance breaks down into six blocks of work. First, classify the product and confirm whether it falls under Annex III (important) or Annex IV (critical), which decides the conformity assessment route. Second, run a cybersecurity risk assessment and close the gaps against the Annex I essential requirements, from secure-by-default configuration to security update handling. Third, assemble the Annex VII technical documentation and sign the EU Declaration of Conformity so the product can carry CE marking. Fourth, publish a coordinated vulnerability disclosure policy and a security contact as Article 13 requires. Fifth, stand up the Article 14 reporting workflow so an actively exploited vulnerability reaches ENISA and your national CSIRT within 24 hours. Sixth, keep an audit trail that proves each obligation was met for the support period you declare.
The interactive checklist below walks through each block. For the legal detail behind every item, the EU Cyber Resilience Act guide explains the regulation article by article, and the product-category checklists cover sector specifics.
Take your results with you
Email yourself a copy or print this page for your compliance file.
CVD Portal covers this checklist end to end, from classification and risk assessment to the Declaration of Conformity and Article 14 filing. New accounts include 14 days of the Compliance plan. Start the CRA self-assessment or see pricing.
Checklist questions, answered
What does CRA compliance require from a manufacturer?
A manufacturer must classify each product with digital elements, run a cybersecurity risk assessment, meet the Annex I essential requirements, assemble technical documentation, sign an EU Declaration of Conformity, affix CE marking, run a coordinated vulnerability disclosure process under Article 13, and report actively exploited vulnerabilities and severe incidents under Article 14.
When do I need to be CRA compliant?
Article 14 reporting applies from 11 September 2026. The remaining obligations, including Annex I, technical documentation, and CE marking, apply from 11 December 2027 to every product with digital elements placed on the EU market.
Does the CRA checklist depend on my product category?
The core obligations are the same for every product with digital elements, but products listed in Annex III (important) or Annex IV (critical) face stricter conformity assessment routes, and some sectors such as medical devices and vehicles are excluded because sector rules already apply.