CRA checklist for EU Cyber Resilience Act readiness
Assess your Cyber Resilience Act readiness across all mandatory requirements. Work through product classification, product security risk assessments, Annex I essential properties, the Declaration of Conformity, and Article 14 reporting deadlines. Built for manufacturers and security teams. Your progress is saved in your browser.
What the CRA requires
The EU Cyber Resilience Act (Regulation (EU) 2024/2847) sets mandatory cybersecurity requirements for every product with digital elements made available on the EU market. Article 14 vulnerability and incident reporting applies from 11 September 2026, and the full regulation, including CE marking, applies from 11 December 2027.
Compliance breaks into six blocks of work, in dependency order. The interactive checklist below walks each of them. For the legal detail behind any item, the EU Cyber Resilience Act guide explains the regulation article by article.
- 1
Classify each product and confirm the conformity route
Establish that the product is in scope, then check its core functionality against the Annex III and Annex IV categories. The class decides whether you can self-assess under module A or need a notified body, which is the only step with a lead time measured in quarters.
The four product classes→ - 2
Run the cybersecurity risk assessment and close the Annex I requirements
The per-product risk assessment determines which Annex I essential requirements apply. Work Part I for the product properties and Part II for vulnerability handling, recording status and evidence per requirement.
Annex I in full→ - 3
Assemble the technical documentation and sign the EU Declaration of Conformity
The Annex VII technical file reports the work above rather than being written separately. The Annex V declaration is a signed legal statement resting on it, and the CE marking follows the declaration.
CE marking under the CRA→ - 4
Publish a vulnerability disclosure policy and a single point of contact
Article 13 requires a coordinated vulnerability disclosure policy and a contact channel researchers can actually reach, plus the Annex II information to users including the support period end date.
Coordinated vulnerability disclosure→ - 5
Stand up the Article 14 reporting workflow
From 11 September 2026 an actively exploited vulnerability starts a 24-hour clock to an early warning, 72 hours to a full notification, and a final report after that, filed through the ENISA single reporting platform.
The ENISA reporting platform→ - 6
Keep an audit trail that proves each obligation was met
Technical documentation is retained for ten years, and the evidence behind each Annex I position needs to survive staff turnover. Record decisions as they happen rather than reconstructing them later.
The eight stages end to end→
Take your results with you
Email yourself a copy or print this page for your compliance file.
CVD Portal covers this checklist end to end, from classification and risk assessment to the Declaration of Conformity and Article 14 filing. Module A self-assessment covers default-class products, and for important and critical products the same workspace prepares the file a notified body assesses. New accounts include 14 days of the Compliance plan. Start the CRA self-assessment or see pricing.
Checklists for your product category
The obligations above are the same for every product with digital elements. What differs is the conformity route and the practical work, so 50 category checklists take the same sequence and apply it to a specific product type.
Consumer Electronics
Industrial & Manufacturing
Healthcare
Networking & IT
Automotive & Transport
Safety & Security
Agriculture
Retail & Hospitality
Checklist questions, answered
What does CRA compliance require from a manufacturer?
A manufacturer must classify each product with digital elements, run a cybersecurity risk assessment, meet the Annex I essential requirements, assemble technical documentation, sign an EU Declaration of Conformity, affix CE marking, run a coordinated vulnerability disclosure process under Article 13, and report actively exploited vulnerabilities and severe incidents under Article 14.
When do I need to be CRA compliant?
Article 14 reporting applies from 11 September 2026. The remaining obligations, including Annex I, technical documentation, and CE marking, apply from 11 December 2027 to every product with digital elements made available on the EU market.
Does the CRA checklist depend on my product category?
The core obligations are the same for every product with digital elements, but products listed in Annex III (important) or Annex IV (critical) face stricter conformity assessment routes. Several categories are outside the CRA entirely because another regime already carries the cybersecurity duty, including medical devices, type-approved vehicles, products certified under the aviation Regulation, and marine equipment under Directive 2014/90/EU.
Is this CRA checklist free, and can I keep the result?
It is free with no signup. Progress is saved in your own browser rather than on our servers, and you can email the completed result to yourself or print it to PDF for the compliance file. Nothing is submitted anywhere unless you choose to email it.