Regulation (EU) 2024/2847 · Manufacturer obligations

CRA for manufacturers

Manufacturers manage CRA compliance by making the product the unit of compliance and working eight stages in dependency order, from scope and classification through the Annex I requirements and the technical file to CE marking and Article 14 reporting. Each stage produces a named artifact, and those artifacts are what a market surveillance authority asks to see.

Why the product is the unit

Almost every CRA obligation attaches to a product rather than to a company. The class is per product. The risk assessment is per product. The Annex I positions, the technical file, the declaration of conformity, the support period and the reporting duty are all per product. A manufacturer with six product lines has six compliance states, and they will not be at the same stage.

This is why company-level compliance tracking breaks down here. A spreadsheet that records the company as 70% ready is describing nothing a market surveillance authority will ever ask about. The question is always whether this product, in this version, has the file that supports the declaration someone signed.

The eight stages

In dependency order. Stage 8 has the earliest deadline, which is the ordering trap covered below.

1

Determine scope

Article 2

Establish whether each product is a product with digital elements placed on the EU market with a data connection, and whether a sector exclusion applies. A company with several product lines will frequently be inside for some and outside for others, and the determination belongs in writing rather than in someone's head.

Produces A recorded in-scope or out-of-scope determination per productCRA scope
2

Classify the product

Articles 7 and 8

Identify the product's core functionality and check it against the Annex III and Annex IV categories. The outcome is default, important Class I, important Class II or critical, and it decides whether you can self-assess or need a notified body. Everything downstream depends on this, so it is the one determination worth getting reviewed.

Produces A class and a conformity assessment routeThe four product classes
3

Assess the risk

Article 13(2)

A per-product risk assessment, kept current, that identifies threats and rates likelihood and impact. Its real job is to decide which Annex I essential requirements apply to this product and why, so an assessment that does not connect to Annex I has not finished.

Produces A documented cybersecurity risk assessmentArticle 13
4

Close the Annex I gaps

Annex I Parts I and II

Part I covers the product properties, Part II the vulnerability handling processes. Track each requirement per product, record which are met, which are not applicable and why, and attach the evidence that supports each position. This is the substance of conformity and the longest stage.

Produces A per-requirement status with evidence attachedThe Annex I checklist
5

Build the technical file

Annex VII

The technical documentation is a generated output of the work above rather than a separate writing exercise. It carries the product description, the classification and its justification, the risk assessment, the Annex I positions with evidence, and the SBOM. Version it per release and keep point-in-time snapshots.

Produces Technical documentation, retained ten yearsAnnex VII
6

Declare and mark

Annex V and Article 30

The declaration is a signed legal statement that the product meets the essential requirements, naming the conformity route taken and, where a notified body was involved, its identification number. The CE marking follows it. This is where a Class II or critical product meets the notified body queue it should have joined a year earlier.

Produces The EU Declaration of Conformity and the CE markingCE marking under the CRA
7

Publish and support

Articles 13 and 14, Annex II

Publish a coordinated vulnerability disclosure policy and a contact channel researchers can reach, state the support period end date, and supply the Annex II information to users from the same record that produced the technical file so the two cannot drift apart.

Produces A CVD policy, a single point of contact, a support periodCoordinated vulnerability disclosure
8

Run the reporting clock

Article 14

On becoming aware of an actively exploited vulnerability or a severe incident, notify the coordinating CSIRT and ENISA within 24 hours, again within 72 hours, and file a final report. This obligation starts on 11 September 2026, ahead of everything above it.

Produces Filed notifications and their referencesCRA reporting obligations

Three sequencing errors that cost the most

All three come from treating the eight stages as independent workstreams rather than as a chain.

1

Reporting binds before the process that feeds it

Article 14 applies from 11 September 2026. The Article 13 obligations that produce your awareness of a vulnerability, the disclosure policy and the single point of contact, do not formally bind until 11 December 2027. The duty that depends on running CVD lands more than a year before the duty to run CVD, so the intake channel is a September 2026 deliverable whatever the calendar says about Article 13.

2

Classification is not a late administrative step

It decides whether a notified body is in the project, and third-party assessment can run 6 to 18 months against limited capacity. A manufacturer that classifies late discovers the queue after the queue has closed. Classify first, then everything else can proceed in parallel.

3

The technical file is an output, not a document sprint

Teams that treat Annex VII as a writing task at the end reconstruct decisions from memory and produce a file that contradicts the product. Recording the classification reasoning, the risk assessment and the Annex I evidence as they happen makes the file a report rather than an archaeology project.

The two dates to plan against

11 September 2026 brings Article 14 into application. From that date an actively exploited vulnerability in your product starts a 24-hour clock. What you need in place by then is an intake channel, a triage process, and somewhere the deadlines are tracked.

11 December 2027 brings the rest, including the Annex I essential requirements, conformity assessment, the technical documentation, the declaration of conformity and CE marking. Products placed on the market after that date need the full file behind them.

Working back from the second date, a Class II or critical product needs its notified body engaged well before then, because assessment alone can take 6 to 18 months. See the full timeline and key dates.

Frequently asked

How do manufacturers manage CRA and product compliance?
By treating the product as the unit of compliance and working eight stages in dependency order. Determine scope, classify the product against Annex III and IV, run a documented risk assessment, close the Annex I essential requirements with evidence, build the Annex VII technical file, issue the EU Declaration of Conformity and apply the CE marking, publish the disclosure policy and support period, and run the Article 14 reporting clock. Each stage produces a named artifact, and the artifacts are what a market surveillance authority asks to see.
What does a manufacturer have to do under the CRA?
Article 13 carries the core duties: design and develop the product to meet the Annex I essential requirements, run and maintain a cybersecurity risk assessment, exercise due diligence on integrated third-party components, produce an SBOM, provide security updates for a defined support period, operate a coordinated vulnerability disclosure policy with a single point of contact, and keep the technical documentation for ten years. Article 14 adds the reporting cascade to ENISA and the coordinating CSIRT.
Where should a manufacturer start with the CRA?
With scope and classification, in that order, and with the disclosure intake channel running in parallel because it has the earlier deadline. Scope tells you which products are in. Classification tells you whether a notified body is involved, which is the only decision with a lead time measured in quarters. Starting instead with Annex I gap analysis is common and wastes effort on products that turn out to need a third-party route nobody booked.
Does the CRA apply to small manufacturers?
Yes. The CRA has no SME exemption from the essential requirements or the reporting duties. What it has is proportionality in how they are met, plus obligations on Member States to support smaller manufacturers, and a lighter regime for open-source software stewards under Article 24. A small manufacturer of a default-class product self-assesses under Module A with no notified body, which is a materially lighter path than the class-based routes.
What are the CRA penalties for manufacturers?
Non-compliance with the Article 13 and Article 14 obligations or the Annex I essential requirements can draw administrative fines of up to 15 million euro or 2.5% of worldwide annual turnover, whichever is higher, under Article 64. Other obligations carry lower ceilings, and supplying incorrect or misleading information to authorities is separately sanctionable. Market surveillance authorities can also restrict or prohibit the product being made available.
How long does CRA compliance take?
For a default-class product with an existing security process, the work is measured in months and is mostly evidence collection and documentation. For a Class II or critical product it is measured against the notified body's calendar, where assessment alone can run 6 to 18 months and the first examination often finds non-conformities needing remediation and re-test. Conformity is due by 11 December 2027, so the higher tiers are already working against the deadline.

Run all eight stages against a product record

CVD Portal holds the classification, the risk assessment, the Annex I positions with their evidence, the generated technical file and declaration, and the disclosure portal that feeds Article 14, all against the same product record. One state per product rather than one percentage per company.

The disclosure portal and report tracking are free. EU data residency by default, no card required to start.

CVD Portal supports CRA compliance work but does not provide legal advice and does not by itself establish conformity or a presumption of conformity. It is an independent platform, not affiliated with or endorsed by the EU or ENISA.