Question 1 01 Which conformity route does a default-tier product use?
EU type-examination performed by a notified body Module A, internal control by the manufacturer Full quality assurance under Module H A European cybersecurity certification scheme at the substantial assurance level
Question 2 02 How is a partner's wholesale discount applied?
As a coupon on the wholesale subscription, so the reduced rate applies automatically As a manual credit the partner has to request from support every month As a year-end rebate paid only after a minimum spend is reached As a discount shown on each client's own invoice so the client sees the wholesale rate
Question 3 03 A sensor reaches the internet only through a separate gateway and never connects directly. Is it in CRA scope?
No, because it has no direct data connection of its own No, indirect connections sit outside Article 2 Yes, an indirect data connection is enough to bring it into scope Only if the gateway and the sensor are sold together as one kit by the same manufacturer
Question 4 04 How are the two parts of Annex I divided?
Part I is paperwork and Part II is marketing material Part I is product security by design and Part II is vulnerability handling after market Part I applies only to hardware and Part II only to software Part I is optional guidance while Part II is the one binding section for manufacturers
Question 5 05 How does a partner operator sign in to the partner console?
As the admin of the partner's own CVD Portal tenant With a dedicated partner-only login separate from any tenant account By signing in to one of the client tenants they operate Only through the phone-sized confirm pages linked from notification emails
Question 6 06 A prospect says, "We already run a bug bounty, so we are covered." What is the strongest response?
Agree that a bug bounty satisfies the CRA and move on to pricing A bug bounty is intake only, while the CRA requires a full handling process, ENISA reporting, and a documented conformity path Explain that bug bounties are banned under the CRA and must be shut down Suggest they hold off on any process work until an external auditor has reviewed the bug bounty in detail and formally confirms whether it satisfies the regulation
Question 7 07 When does the CRA Article 14 reporting duty begin?
11 December 2027 1 January 2025 11 September 2026 It has no fixed start date
Question 8 08 How often can the daily cross-client review digest repeat?
On every single client action No more than once within a day, and each partner admin can turn it off Once a week only, with no option to disable it It is sent separately for each client rather than once per partner
Question 9 09 Within how long must a manufacturer acknowledge a vulnerability report it receives?
24 hours 72 hours 48 hours There is no fixed acknowledgment deadline anywhere in the CRA
Question 10 10 What conformity involvement does an Annex III Class II product always require?
Self-assessment by the manufacturer working alone A third party, such as a notified body No assessment of any kind before 2030 Only a self-declaration published on the manufacturer's own website with no further steps
Question 11 11 When is the Article 14 final report on an exploited vulnerability due?
Immediately, alongside the 24-hour early warning Never, because the 72-hour notification is the last required step Within 14 days of a corrective measure becoming available Within six months of the vulnerability first being discovered by anyone at all
Question 12 12 A client insists on paying CVD Portal directly and paying the partner only for advisory work. Which billing choice fits, and where is it set?
Wholesale billing, set once for the whole partner account Client-direct billing, chosen per client in the console Wholesale billing, chosen per client in the console There is no supported way to let a client pay the platform directly
Question 13 13 Which product sits in Annex IV, the critical tier?
A hardware security module A consumer router for home use An internet-connected children's toy A password manager application for individuals
Question 14 14 For how long must security updates stay available after a product is placed on the market?
At least 10 years, or the rest of the support period if that is longer At least two years from first sale Only for the calendar year in which it was sold Only until the next major version of the product is released to the market
Question 15 15 A consultant uploads a 20-file batch of mixed datasheets and manuals, then leaves the office. What happens when the batch finishes reading?
The documents are dispatched automatically once reading completes The partner admins get an email deep-linking to a mobile confirm page The batch is discarded if the partner does not return within the hour Nothing happens until the consultant reopens the console on a laptop