What documentation does the CRA require?
Technical documentation under Annex VII
The technical documentation covers the product description, design and development information, the cybersecurity risk assessment, vulnerability handling processes, applied standards, and test results. Draw it up before placing the product on the market and keep it current.
EU declaration of conformity under Annex V
It includes product identification, the manufacturer's name and address, a sole-responsibility statement, the object of the declaration, the standards applied, and any notified body involved. Annex VI allows a simplified declaration that links to the full text.
Information and instructions to the user under Annex II
Users must receive the manufacturer's contact point, product identification, intended use, known or foreseeable circumstances leading to significant cybersecurity risk, the vulnerability reporting address, and the support period end date.
The support period end date must reach the user. Documenting it internally is not enough.
How long must CRA documentation be kept?
At least 10 years after the product is placed on the market, or for the support period, whichever is longer.
How do CRA requirements change by product class?
The CRA sorts products into classes by how much damage a compromise could cause: Default, Important Class I, Important Class II, and Critical.
Every class must meet the same 21 requirements. What changes is how you prove conformity: the higher the risk, the more likely it is you need an independent assessment of your product security.
Default products and self-assessment
Most products fit into the "default" category. For these, you check compliance yourself (known as the "module A" internal control procedure), write the technical documentation, and sign the declaration of conformity. No outside assessor is involved. Default products are those not listed in Annex III or Annex IV.
Important products, Annex III Class I
Examples for this class include identity and access management software, browsers, password managers, antimalware, VPNs, network management systems, SIEM, boot managers, PKI software, network interfaces, operating systems, routers and modems, security-related microprocessors and microcontrollers, smart home assistants, smart locks and cameras, connected toys with social or tracking features, and wearables with health tracking or intended for children.
You can self-assess only if you fully apply harmonized standards, common specifications, or a European cybersecurity certification. Otherwise, you'll need a third-party assessment.
Important products, Annex III Class II
This class covers hypervisors and container runtime systems, firewalls and intrusion detection and prevention systems, and tamper-resistant microprocessors and microcontrollers. Class II generally needs a higher-assurance, third-party assessment.
Critical products under Annex IV
Critical products are hardware devices with security boxes, smart meter gateways, and smartcards and secure elements. They may be subject to mandatory European cybersecurity certification.