CRA for manufacturers
Manufacturers manage CRA compliance by making the product the unit of compliance and working eight stages in dependency order, from scope and classification through the Annex I requirements and the technical file to CE marking and Article 14 reporting. Each stage produces a named artifact, and those artifacts are what a market surveillance authority asks to see.
Why the product is the unit
Almost every CRA obligation attaches to a product rather than to a company. The class is per product. The risk assessment is per product. The Annex I positions, the technical file, the declaration of conformity, the support period and the reporting duty are all per product. A manufacturer with six product lines has six compliance states, and they will not be at the same stage.
This is why company-level compliance tracking breaks down here. A spreadsheet that records the company as 70% ready is describing nothing a market surveillance authority will ever ask about. The question is always whether this product, in this version, has the file that supports the declaration someone signed.
The eight stages
In dependency order. Stage 8 has the earliest deadline, which is the ordering trap covered below.
Determine scope
Article 2Establish whether each product is a product with digital elements placed on the EU market with a data connection, and whether a sector exclusion applies. A company with several product lines will frequently be inside for some and outside for others, and the determination belongs in writing rather than in someone's head.
Classify the product
Articles 7 and 8Identify the product's core functionality and check it against the Annex III and Annex IV categories. The outcome is default, important Class I, important Class II or critical, and it decides whether you can self-assess or need a notified body. Everything downstream depends on this, so it is the one determination worth getting reviewed.
Assess the risk
Article 13(2)A per-product risk assessment, kept current, that identifies threats and rates likelihood and impact. Its real job is to decide which Annex I essential requirements apply to this product and why, so an assessment that does not connect to Annex I has not finished.
Close the Annex I gaps
Annex I Parts I and IIPart I covers the product properties, Part II the vulnerability handling processes. Track each requirement per product, record which are met, which are not applicable and why, and attach the evidence that supports each position. This is the substance of conformity and the longest stage.
Build the technical file
Annex VIIThe technical documentation is a generated output of the work above rather than a separate writing exercise. It carries the product description, the classification and its justification, the risk assessment, the Annex I positions with evidence, and the SBOM. Version it per release and keep point-in-time snapshots.
Declare and mark
Annex V and Article 30The declaration is a signed legal statement that the product meets the essential requirements, naming the conformity route taken and, where a notified body was involved, its identification number. The CE marking follows it. This is where a Class II or critical product meets the notified body queue it should have joined a year earlier.
Publish and support
Articles 13 and 14, Annex IIPublish a coordinated vulnerability disclosure policy and a contact channel researchers can reach, state the support period end date, and supply the Annex II information to users from the same record that produced the technical file so the two cannot drift apart.
Run the reporting clock
Article 14On becoming aware of an actively exploited vulnerability or a severe incident, notify the coordinating CSIRT and ENISA within 24 hours, again within 72 hours, and file a final report. This obligation starts on 11 September 2026, ahead of everything above it.
Three sequencing errors that cost the most
All three come from treating the eight stages as independent workstreams rather than as a chain.
Reporting binds before the process that feeds it
Article 14 applies from 11 September 2026. The Article 13 obligations that produce your awareness of a vulnerability, the disclosure policy and the single point of contact, do not formally bind until 11 December 2027. The duty that depends on running CVD lands more than a year before the duty to run CVD, so the intake channel is a September 2026 deliverable whatever the calendar says about Article 13.
Classification is not a late administrative step
It decides whether a notified body is in the project, and third-party assessment can run 6 to 18 months against limited capacity. A manufacturer that classifies late discovers the queue after the queue has closed. Classify first, then everything else can proceed in parallel.
The technical file is an output, not a document sprint
Teams that treat Annex VII as a writing task at the end reconstruct decisions from memory and produce a file that contradicts the product. Recording the classification reasoning, the risk assessment and the Annex I evidence as they happen makes the file a report rather than an archaeology project.
The two dates to plan against
11 September 2026 brings Article 14 into application. From that date an actively exploited vulnerability in your product starts a 24-hour clock. What you need in place by then is an intake channel, a triage process, and somewhere the deadlines are tracked.
11 December 2027 brings the rest, including the Annex I essential requirements, conformity assessment, the technical documentation, the declaration of conformity and CE marking. Products placed on the market after that date need the full file behind them.
Working back from the second date, a Class II or critical product needs its notified body engaged well before then, because assessment alone can take 6 to 18 months. See the full timeline and key dates.
Frequently asked
How do manufacturers manage CRA and product compliance?
What does a manufacturer have to do under the CRA?
Where should a manufacturer start with the CRA?
Does the CRA apply to small manufacturers?
What are the CRA penalties for manufacturers?
How long does CRA compliance take?
Run all eight stages against a product record
CVD Portal holds the classification, the risk assessment, the Annex I positions with their evidence, the generated technical file and declaration, and the disclosure portal that feeds Article 14, all against the same product record. One state per product rather than one percentage per company.
The disclosure portal and report tracking are free. EU data residency by default, no card required to start.
CVD Portal supports CRA compliance work but does not provide legal advice and does not by itself establish conformity or a presumption of conformity. It is an independent platform, not affiliated with or endorsed by the EU or ENISA.