CRA ComplianceLast updated 2026-08-30

What is a CRA compliance platform and what does it replace?

A CRA compliance platform carries one product through every Cyber Resilience Act obligation, from Annex III classification to Article 14 reporting, and replaces six manual artifacts, starting with a hosted policy page and a spreadsheet of acknowledgment deadlines.

Key takeaways

  • A CRA compliance platform guides one product through every Cyber Resilience Act obligation from product classification to authority reporting.
  • A platform replaces the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file.
  • Article 14 reporting obligations for actively exploited vulnerabilities apply from 11 September 2026.
  • Essential cybersecurity requirements, technical documentation, and EU Declarations of Conformity under Article 71(2) apply from 11 December 2027.
  • Module A self-assessment is open to default-class products, whereas important and critical products require third-party assessment by a notified body or certification scheme.

The six artifacts a platform replaces

A CRA compliance platform replaces six manual artifacts. The six artifacts are the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file.

Managing these artifacts by hand creates coordination risks during an audit or a security incident. A platform generates the artifacts from a single recorded state, across 88 CRA clause artifacts and 33 security objectives. That unified record prevents inconsistencies between published policies and internal files.

Which obligation a platform carries, and from when

Article 14 reporting applies from 11 September 2026. Every other obligation in the table applies from 11 December 2027 under Article 71(2).

CRA obligationWithout a platformWith a CRA compliance platformApplies from
Article 13 CVD policyHand-built policy page and shared inboxBranded portal, hosted policy, structured intake with PGP11 December 2027
Article 14 reportingManual deadline tracking in a spreadsheetHard timers on 24h, 72h, and final report, SRP-ready package11 September 2026
Article 13 risk assessmentAd-hoc document per productSTRIDE assessment mapped onto Annex I requirements11 December 2027
Technical documentationFolder tree standing in for the fileAnnex VII index and Annex V DoC generated from state11 December 2027
AdvisoriesBespoke advisory documentsCSAF 2.0 machine-readable advisory on remediation11 December 2027

Where a platform stops

A CRA compliance platform produces the technical file and the Annex I evidence. A notified body or a certification scheme carries the assessment of that file where the product class requires one.

Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.

Manufacturers of default-class products can complete CRA self-assessment internally using the platform. Important and critical products require engagement with an accredited conformity assessment body.

Why the unit of work differs from a GRC tool

A generic governance, risk and compliance tool records controls at the organisation level. Cyber Resilience Act conformity attaches to one product and one release, so the unit of work differs.

That difference shows up in the outputs. Regulation (EU) 2024/2847 asks for a per-product software bill of materials, a documented risk assessment per product, an Annex VII technical file per release, and a machine-readable advisory when a fix ships. A platform built around the product record produces each one from that record. A platform built around a management system records the policy that governs the work.

Sources

Last updated 30 August 2026.

Published by Porta Regulus B.V. Our editorial policy carries the company registration.

Article 14 reporting applies from 11 September 2026.

Get started free

Frequently asked questions

What is a CRA compliance platform?

A CRA compliance platform is software that carries a product with digital elements through every Cyber Resilience Act obligation. It covers product classification, cybersecurity risk assessment, Annex I essential requirements, technical documentation, the EU Declaration of Conformity, vulnerability handling, and Article 14 authority reporting.

What does a CRA compliance platform replace?

A CRA compliance platform replaces six manual artifacts. The six artifacts are the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file.

Does a CRA compliance platform replace a notified body?

A CRA compliance platform prepares technical documentation and Annex I evidence for manufacturer self-assessment and third-party review. Default-class products use Module A self-assessment. Important products under Annex III and critical products under Annex IV require a notified body or a European cybersecurity certification scheme.

Can a generic GRC tool cover the Cyber Resilience Act?

A generic GRC tool records compliance controls at the organisation level. Cyber Resilience Act conformity attaches to a specific product and release. A CRA compliance platform manages per-product technical documentation, component inventories, and Article 14 statutory reporting timers.

When do the obligations a platform covers start applying?

Article 14 reporting obligations for actively exploited vulnerabilities apply from 11 September 2026. The remaining obligations, including essential cybersecurity requirements and technical documentation under Article 71(2), apply from 11 December 2027.