← CRA FAQObligations in practice

What documents and reports does the Cyber Resilience Act require me to produce?

Also asked

  • What goes in CRA technical documentation?
  • Is an SBOM mandatory under the Cyber Resilience Act?
  • How long must I keep CRA compliance records?
  • Who is allowed to ask to see my CRA documentation?
  • What is the difference between Annex II and Annex VII?

The Cyber Resilience Act requires six artefacts. Technical documentation under Article 31 and Annex VII, which contains the risk assessment. An EU declaration of conformity under Article 28 and Annex V. A software bill of materials and a coordinated vulnerability disclosure policy, both under Annex I Part II. Information and instructions to the user under Annex II. Then the Article 14 filings once reporting begins. Technical documentation and the declaration are kept available to market surveillance authorities for at least 10 years or the support period, whichever is longer.

Only the Annex II user information and the CE marking travel with the product. Everything else is held and produced on request, which is why the retention rule matters as much as the drafting.

At a glance

Technical documentation
Article 31 and Annex VII, includes the risk assessment
EU declaration of conformity
Article 28 and Annex V
SBOM
Annex I Part II(1), machine-readable, top-level dependencies minimum
CVD policy
Annex I Part II(5), plus a reporting contact address
User information
Annex II, supplied with the product
Retention
At least 10 years, or the support period if longer

Last reviewed 27 July 2026

Verified against The final text of Regulation (EU) 2024/2847 as published in OJ L, 20.11.2024, read at EUR-Lex on 27 July 2026

Technical documentation, the file everything else feeds

Article 31 requires technical documentation containing all relevant data and details of the means used to demonstrate conformity with the essential requirements, drawn up before the product is placed on the market and kept up to date.[3]

Annex VII sets the contents, and it is broader than a design dossier. It requires:[9]

  1. A general description of the product, covering its intended purpose, the software versions affecting compliance, photographs or illustrations of external features, marking and internal layout for hardware, and the Annex II user information.
  2. A description of design, development and production and of the vulnerability handling processes. This is where the software bill of materials, the coordinated vulnerability disclosure policy, evidence of a reporting contact address and a description of the secure update distribution mechanism all live.
  3. An assessment of the cybersecurity risks the product is designed, developed, produced, delivered and maintained against, pursuant to Article 13.

Two consequences follow. The SBOM and the CVD policy are Annex I obligations in their own right, and they are also line items in the technical file, so producing them without filing them leaves the file incomplete. And Article 13(4) requires the risk assessment to be included here, along with a clear justification wherever an essential requirement is treated as not applicable.[1]

CRA referenceArticle 31, Annex VII, Article 13(4)

The EU declaration of conformity

Article 28 requires the manufacturer to draw up the EU declaration of conformity, stating that fulfilment of the applicable Annex I essential requirements has been demonstrated. It follows the model structure in Annex V, carries the elements specified in the relevant Annex VIII conformity assessment procedure, and is updated as appropriate.[2]

Annex V lists what it must contain, including the name and type and any additional information uniquely identifying the product, the name and address of the manufacturer or authorised representative, a statement that the declaration is issued under sole responsibility, the object of the declaration allowing traceability, a statement of conformity with the relevant Union harmonisation legislation, and references to any harmonised standards, common specifications or cybersecurity certification relied on.[8]

That last element is the one to watch. It records which standards you leaned on, and since no CRA harmonised standard is yet cited in the Official Journal, most declarations drawn up today will have nothing to put there. The EN 40000 timing question covers what that means for the assessment route.

Article 13(12) sequences it. Once the conformity assessment procedure has demonstrated compliance, the manufacturer draws up the declaration under Article 28 and affixes the CE marking under Article 30.[1]

CRA referenceArticle 28, Annex V, Article 13(12)

The SBOM and the disclosure policy

Both come from Annex I Part II, the process half of the essential requirements, and both apply regardless of what the risk assessment concludes.

Part II point (1) requires manufacturers to identify and document vulnerabilities and components contained in the product, including by drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies of the product.[6]

Two details in that wording carry weight. Machine-readable rules out a spreadsheet of component names, which points at SPDX or CycloneDX. And top-level dependencies is a floor rather than a target, so deeper transitive coverage is permitted and often necessary to answer a vulnerability question quickly.

Part II point (5) requires a policy on coordinated vulnerability disclosure to be put in place and enforced. Point (4) requires public disclosure of fixed vulnerabilities once a security update is available, including a description, information letting users identify affected products, the impacts, the severity, and clear information helping users remediate. Where a manufacturer judges the security risks of publication to outweigh the benefits, publication may be delayed in duly justified cases until users have had the chance to apply the patch.[6]

Annex II point 2 then requires the single point of contact for vulnerability reports, and where the CVD policy can be found, to be supplied with the product.[7]

CRA referenceAnnex I Part II, points (1), (4) and (5)

Annex II, the only document that ships with the product

Annex VII is held for authorities. Annex II goes to users, and the two are regularly confused.

Annex II requires the product to be accompanied, at minimum, by the manufacturer's name and contact details, the single point of contact for vulnerability reports and where the CVD policy can be found, information uniquely identifying the product, the intended purpose including the security environment provided by the manufacturer and the product's essential functionalities and security properties, any known or foreseeable circumstance related to intended use or reasonably foreseeable misuse that may lead to significant cybersecurity risks, where applicable the internet address for the EU declaration of conformity, and the type of technical security support offered with the end date of the support period.[7]

Article 13 sets the quality bar and the retention. The information and instructions must be in a language easily understood by users and market surveillance authorities, and be clear, understandable, intelligible and legible. They are kept at the disposal of users and market surveillance authorities for at least 10 years after the product is placed on the market, or for the support period, whichever is longer.[1]

Publishing the support period end date here is the commitment most manufacturers underestimate, because it fixes in public the date their Annex I Part II obligations stop.

CRA referenceAnnex II, Article 13

The reports you file rather than hold

Everything above is produced once and maintained. The Article 14 reports are events.

For an actively exploited vulnerability: an early warning within 24 hours, a vulnerability notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure is available. For a severe incident: 24 hours, 72 hours, and a final report within one month of the 72-hour notification. All filed through the ENISA single reporting platform to a coordinating CSIRT, and simultaneously accessible to ENISA.[4]

Article 14(8) adds a communication to users, which where appropriate should be in a structured, machine-readable format that is easily automatically processable. That clause is the practical case for issuing a CSAF advisory rather than a prose bulletin.[4][10]

The CSIRT routing and platform mechanics work through who receives these and how. Note also that where the same event engages NIS2 or GDPR, those regimes require their own separate filings on their own clocks.

CRA referenceArticle 14(2), (4) and (8)

Who can ask, and how long you keep it

The retention rules are separate obligations and they outlive the support period.

Article 13(13) requires manufacturers to keep the technical documentation and the EU declaration of conformity at the disposal of market surveillance authorities for at least 10 years after the product has been placed on the market, or for the support period, whichever is longer.[1]

The same 10-year-or-support-period rule applies to the Annex II information and instructions, held at the disposal of users as well as authorities.[1]

Article 13(9) runs a different clock that is easy to misread. Each security update made available during the support period must remain available after it has been issued for a minimum of 10 years, or for the remainder of the support period, whichever is longer.[1] The clock starts when the update is issued, not when the product was placed on the market, so an update shipped in year eight of a product's life has to stay available into year eighteen.

Market surveillance authorities are the audience with a right of access, under the Chapter V powers. Notified bodies see the documentation where a third-party conformity assessment route applies. Users receive Annex II and the security updates.

CRA referenceArticle 13(9) and (13)

What actually satisfies an authority

Two structural features of the Regulation decide whether a document set holds up.

It has to be current. Article 31 requires the technical documentation to be kept up to date, and Article 13(3) requires the risk assessment to be documented and updated as appropriate during the support period.[3][1] A file that reflects the product as launched, on a product that has shipped eleven releases since, is a file that no longer describes the product on the market.

It has to explain its own gaps. Article 13(4) requires a clear justification in the technical documentation wherever an essential cybersecurity requirement is not applicable.[1] Since Annex I Part I point (2) applies its requirements only on the basis of the risk assessment and where applicable, the exclusions are as load-bearing as the inclusions, and an unexplained absence reads as an omission.[6]

There is one form-level concession. Article 33(5) allows microenterprises and small enterprises to supply all Annex VII elements using a simplified format specified by the Commission in an implementing act, and notified bodies have to accept it. It changes the form, and the substance is unchanged.[5]

CRA referenceArticle 13(3) and (4), Article 31, Article 33(5)

Sources

Every claim above traces to one of these. Items marked Binding are law in force. Everything else is interpretive and is labelled as such.

  1. [1]

    Publications Office of the European Union · Article 13(3), (4), (9), (12), (13) and (18) · CELEX:32024R2847 · OJ L, 20.11.2024

    keep the technical documentation and the EU declaration of conformity at the disposal of the market surveillance authorities for at least 10 years

    Accessed 2026-07-27

  2. [2]

    Publications Office of the European Union · Article 28(1) and (2) · CELEX:32024R2847

    state that the fulfilment of the applicable essential cybersecurity requirements set out in Annex I has been demonstrated

    Accessed 2026-07-27

  3. [3]

    Publications Office of the European Union · Article 31, with Annex VII · CELEX:32024R2847

    Accessed 2026-07-27

  4. [4]

    Publications Office of the European Union · Article 14(2), (4) and (8) · CELEX:32024R2847

    Accessed 2026-07-27

  5. [5]

    Publications Office of the European Union · Article 33(5) · CELEX:32024R2847

    Microenterprises and small enterprises may provide all elements of the technical documentation specified in Annex VII by using a simplified format

    Accessed 2026-07-27

  6. [6]

    Publications Office of the European Union · Annex I Part II, points (1), (4) and (5) · CELEX:32024R2847

    drawing up a software bill of materials in a commonly used and machine-readable format covering at the very least the top-level dependencies

    Accessed 2026-07-27

  7. [7]

    Publications Office of the European Union · Annex II, points 1 to 7 · CELEX:32024R2847

    the single point of contact where information about vulnerabilities of the product with digital elements can be reported and received

    Accessed 2026-07-27

  8. [8]

    Publications Office of the European Union · Annex V, points 1 to 6 · CELEX:32024R2847

    Accessed 2026-07-27

  9. [9]

    Publications Office of the European Union · Annex VII, points 1 to 3 · CELEX:32024R2847

    necessary information and specifications of the vulnerability handling processes put in place by the manufacturer, including the software bill of materials

    Accessed 2026-07-27

  10. [10]

    OASIS Open · OASIS Standard, CSAF 2.0

    An industry standard for machine-readable advisories. The CRA requires a structured, machine-readable format where appropriate without naming CSAF.

    Accessed 2026-07-27

  11. [11]

    Linux Foundation and OASIS Open · ISO/IEC 5962:2021 (SPDX), CycloneDX

    The two formats in common use. Annex I Part II requires a commonly used machine-readable format without naming either.

    Accessed 2026-07-27

  12. [12]

    Bundesamt für Sicherheit in der Informationstechnik · BSI TR-03183-2

    Guidance from a national authority setting concrete SBOM field expectations against CRA obligations. It carries no presumption of conformity.

    Accessed 2026-07-27

Follow-up questions

What format and depth does the CRA expect from an SBOM?+

Annex I Part II point (1) requires a commonly used, machine-readable format covering at the very least the top-level dependencies. Machine-readable rules out a spreadsheet of component names, which in practice points at SPDX or CycloneDX. Top-level is a floor rather than a target, and deeper transitive coverage is often needed to answer a vulnerability question quickly. Annex VII then lists the SBOM as an element of the technical documentation, so it has to exist and be filed.

Do I have to publish the SBOM?+

No. The SBOM sits in the technical documentation, which is kept at the disposal of market surveillance authorities rather than published. What is public-facing is the Annex II user information, the disclosure of fixed vulnerabilities under Annex I Part II point (4), and where applicable the internet address for the EU declaration of conformity.

What is the difference between Annex II and Annex VII?+

Annex VII is the technical documentation, held for market surveillance authorities and notified bodies. Annex II is the information and instructions that accompany the product to the user. Annex II is itself listed as an element of the Annex VII file, so the user-facing document is a component of the authority-facing one.

How long do I keep the records after a product is discontinued?+

Article 13(13) sets at least 10 years after the product was placed on the market, or the support period if longer, for the technical documentation and the EU declaration of conformity. Discontinuing sales does not restart or shorten that clock, and Article 13(9) separately keeps each issued security update available for at least 10 years from issue.

Does a template pack make us compliant?+

No. Article 31 requires the documentation to contain the means used to demonstrate conformity for the actual product, Article 13(4) requires a reasoned justification for every requirement treated as inapplicable, and both the file and the risk assessment have to be kept current. A template establishes the structure, and the evidence is what is assessed.

Work out where your product actually lands

Free CRA classification for your product, a vulnerability disclosure portal on your own domain, and Article 14 deadline tracking. Receiving and tracking reports is free for every manufacturer placing products with digital elements on the EU market.