CRA readiness
Getting a manufacturer ready for the CRA: class, route, vulnerability handling, support period, the technical file, and a rehearsed reporting clock.
Governance6 Sept 20265 min read
On this page
Scope
Two clocks run at once. Article 14 applies from 11 September 2026, reaching products already on the market 1. The rest applies from 11 December 2027 2.
The gap is ownership, not knowledge. Roadmap, code and policy each have an owner; the manufacturer's duty has none. One loop closes it: governance decides the route and names the signatory, risk supplies the documented assessment and the component position, compliance leaves the file, the declaration and the reporting evidence.
In scope: class, route, vulnerability handling, the support period, the file, a rehearsed reporting path.
Out of scope: engineering the product, the assessment body's work, market surveillance.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Scope and class | Which products, which annex category | 3–5 weeks | Each product has a class decision |
| 2. Route | The Article 32 procedure and the signatory | 4–8 weeks | Each route is recorded with its reason |
| 3. Vulnerability handling | Intake, triage, update, disclosure — vulnerability handling and SBOM | 3–5 months | One record reaches disclosure |
| 4. Support period and components | The period, a position per outside component | 6–10 weeks | Each product has a dated period |
| 5. Documentation | The Annex VII file and the declaration — CRA technical documentation | 3–5 months | A reader of the file signs it |
| 6. Article 14 rehearsal | A timed run against the clocks | 2–4 weeks | Each notification lands inside its clock |
Phase 2 is governance's decision, phase 4 risk's instrument, phase 5 what compliance shows an authority.
Annex III core functionality makes a product important, Annex IV critical 3: obligations by product class. Class decides which Annex VIII procedures stay open 4: the conformity route. The period follows expected use, with a five-year floor unless that use is shorter 5: the support period decision. Components carry due diligence; a vulnerability in one goes to its maintainer 6: supply chain and components. Phase 6 tests 24 hours, 72 hours, then 14 days or one month 7: /radar#cra-reporting-obligations.
Deliverables
- Product inventory, class and route per product — everything else follows.
- Class and route decision record, with the signatory — why each route was chosen.
- Vulnerability handling record, one per issue — vulnerability handling record.
- Support-period statement and the component positions behind it — the reasoning, not the date.
- Annex VII file index and the signed declaration — CRA technical documentation index.
- Reporting rehearsal record, timed against each clock — proof the path works.
Roles
| Role | Side | Accountable for |
|---|---|---|
| Manufacturer | Organisation | The essential requirements, at the moment of placing 8 |
| Product security owner | Organisation | The risk assessment, documented and kept current 9 |
| Compliance owner | Organisation | The file and declaration, at authorities' disposal for ten years or the support period 10 |
| Incident owner | Organisation | The reporting path and its rehearsal |
| Product management | Organisation | The support period and the class decision each product keys to |
| Adviser | External | Method, the class and route reasoning, rehearsal design |
What the authority asks
Failure modes
Frameworks
| Instrument | What it asks | Where it lands |
|---|---|---|
| Regulation (EU) 2024/2847 | A documented assessment, current, available to authorities | Articles 13(2), 13(3), 13(13) |
| IEC 62443-4-1:2018 | Justified scoping, outside components, update timing | SM-5, SM-9, SUM-5 11 |
| ISO/SAE 21434:2021 | Reviewed tailoring and assessment rationales, an incident response plan | Clauses 6.4.3, 6.4.8, 13.3 12 |
| ISO/IEC 27001:2022 | Authorities, risk actions, operational control, audit | Clauses 5.3, 6.1, 8.1, 9.2 13 |
The boundary with the CSMS and the ISMS
The product cybersecurity pattern builds a management system and its certificate. This work borrows ISMS machinery: authorities, operational control, an audit programme. The duty cannot be borrowed. Where both apply, governing security in the product organisation holds the decision rights.
Related
- What to do first under the CRA — the decisions to take before a programme exists.
- /radar#cra-commission-guidance — the Commission's reading of scope, modification and support periods.
References
- European Parliament and Council. Regulation (EU) 2024/2847. OJ L, 2024/2847, 20.11.2024 14.
- IEC. IEC 62443-4-1:2018.
https://webstore.iec.ch/en/publication/33615. Identifiers and titles, licensed copy, 2026-09-06. - ISO and SAE International. ISO/SAE 21434:2021.
https://www.iso.org/standard/70918.html. Clauses and titles, licensed copy, 2026-09-06. - ISO/IEC. ISO/IEC 27001:2022.
https://www.iso.org/standard/27001. Clause titles from the ISO Online Browsing Platform, 2026-09-03.
Sources
- 1EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(3) · verified 2026-09-05
- 2EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(2) · verified 2026-09-05
- 3EU Publications Office CELEX 32024R2847 Art. 7(1), Art. 8(1), Annex III and Annex IV · verified 2026-09-05
- 4EU Publications Office CELEX 32024R2847 Art. 32(1) to 32(4) · verified 2026-09-05
- 5EU Publications Office CELEX 32024R2847 Art. 13(8) · verified 2026-09-05
- 6EU Publications Office CELEX 32024R2847 Art. 13(5) and Art. 13(6) · verified 2026-09-05
- 7EU Publications Office CELEX 32024R2847 Art. 14(2) and 14(4) · verified 2026-09-05
- 8EU Publications Office CELEX 32024R2847 Art. 13(1) and Annex I Part I · verified 2026-09-04
- 9EU Publications Office CELEX 32024R2847 Art. 13(2) and 13(3) · verified 2026-09-05
- 10EU Publications Office CELEX 32024R2847 Art. 13(13) · verified 2026-09-05
- 11IEC 62443-4-1:2018 SM-5, SM-9 and SUM-5, licensed copy · verified 2026-09-06
- 12ISO/SAE 21434:2021 clauses 6.4.3, 6.4.8 and 13.3, licensed copy · verified 2026-09-06
- 13ISO/IEC 27001:2022 clauses 5.3, 6.1, 8.1 and 9.2, iso.org/obp · verified 2026-09-03
- 14EU Publications Office CELEX 32024R2847, full text · verified 2026-09-05