A CRA compliance platform carries one product through every Cyber Resilience Act obligation, from Annex III classification to Article 14 reporting, and replaces six manual artifacts, starting with a hosted policy page and a spreadsheet of acknowledgment deadlines.
Key takeaways
- A CRA compliance platform guides one product through every Cyber Resilience Act obligation from product classification to authority reporting.
- A platform replaces the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file.
- Article 14 reporting obligations for actively exploited vulnerabilities apply from 11 September 2026.
- Essential cybersecurity requirements, technical documentation, and EU Declarations of Conformity under Article 71(2) apply from 11 December 2027.
- Module A self-assessment is open to default-class products, whereas important and critical products require third-party assessment by a notified body or certification scheme.
The six artifacts a platform replaces
A CRA compliance platform replaces six manual artifacts. The six artifacts are the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file.
Managing these artifacts by hand creates coordination risks during an audit or a security incident. A platform generates the artifacts from a single recorded state, across 88 CRA clause artifacts and 33 security objectives. That unified record prevents inconsistencies between published policies and internal files.
Which obligation a platform carries, and from when
Article 14 reporting applies from 11 September 2026. Every other obligation in the table applies from 11 December 2027 under Article 71(2).
| CRA obligation | Without a platform | With a CRA compliance platform | Applies from |
|---|---|---|---|
| Article 13 CVD policy | Hand-built policy page and shared inbox | Branded portal, hosted policy, structured intake with PGP | 11 December 2027 |
| Article 14 reporting | Manual deadline tracking in a spreadsheet | Hard timers on 24h, 72h, and final report, SRP-ready package | 11 September 2026 |
| Article 13 risk assessment | Ad-hoc document per product | STRIDE assessment mapped onto Annex I requirements | 11 December 2027 |
| Technical documentation | Folder tree standing in for the file | Annex VII index and Annex V DoC generated from state | 11 December 2027 |
| Advisories | Bespoke advisory documents | CSAF 2.0 machine-readable advisory on remediation | 11 December 2027 |
Where a platform stops
A CRA compliance platform produces the technical file and the Annex I evidence. A notified body or a certification scheme carries the assessment of that file where the product class requires one.
Module A self-assessment is open to default-class products. Important products (Annex III) and critical products (Annex IV) need a notified body or a European cybersecurity certification scheme and must comply with specific vertical standards, because no CRA harmonised standard is cited in the Official Journal yet. For those, CVD Portal prepares the technical file and the Annex I evidence the assessment body asks for, and does not replace it.
Manufacturers of default-class products can complete CRA self-assessment internally using the platform. Important and critical products require engagement with an accredited conformity assessment body.
Why the unit of work differs from a GRC tool
A generic governance, risk and compliance tool records controls at the organisation level. Cyber Resilience Act conformity attaches to one product and one release, so the unit of work differs.
That difference shows up in the outputs. Regulation (EU) 2024/2847 asks for a per-product software bill of materials, a documented risk assessment per product, an Annex VII technical file per release, and a machine-readable advisory when a fix ships. A platform built around the product record produces each one from that record. A platform built around a management system records the policy that governs the work.
Sources
- Regulation (EU) 2024/2847, Article 13
- Regulation (EU) 2024/2847, Article 14
- Regulation (EU) 2024/2847, Article 71
- Regulation (EU) 2024/2847, Annex III
- Regulation (EU) 2024/2847, Annex VII
Last updated 30 August 2026.
Published by Porta Regulus B.V. Our editorial policy carries the company registration.
Article 14 reporting applies from 11 September 2026.
Get started freeFrequently asked questions
What is a CRA compliance platform?
A CRA compliance platform is software that carries a product with digital elements through every Cyber Resilience Act obligation. It covers product classification, cybersecurity risk assessment, Annex I essential requirements, technical documentation, the EU Declaration of Conformity, vulnerability handling, and Article 14 authority reporting.
What does a CRA compliance platform replace?
A CRA compliance platform replaces six manual artifacts. The six artifacts are the hosted policy page, the shared intake inbox, the acknowledgment-tracking spreadsheet, manual deadline reminders, bespoke advisory documents, and the folder tree standing in for the technical file.
Does a CRA compliance platform replace a notified body?
A CRA compliance platform prepares technical documentation and Annex I evidence for manufacturer self-assessment and third-party review. Default-class products use Module A self-assessment. Important products under Annex III and critical products under Annex IV require a notified body or a European cybersecurity certification scheme.
Can a generic GRC tool cover the Cyber Resilience Act?
A generic GRC tool records compliance controls at the organisation level. Cyber Resilience Act conformity attaches to a specific product and release. A CRA compliance platform manages per-product technical documentation, component inventories, and Article 14 statutory reporting timers.
When do the obligations a platform covers start applying?
Article 14 reporting obligations for actively exploited vulnerabilities apply from 11 September 2026. The remaining obligations, including essential cybersecurity requirements and technical documentation under Article 71(2), apply from 11 December 2027.