Back to engagement patterns
    Engagement pattern

    CRA readiness

    Getting a manufacturer ready for the CRA: class, route, vulnerability handling, support period, the technical file, and a rehearsed reporting clock.

    Governance6 Sept 20265 min read

    IEC 62443-4-1:2018ISO/IEC 27001:2022ISO/SAE 21434:2021Regulation (EU) 2024/2847
    On this page

    Scope

    Two clocks run at once. Article 14 applies from 11 September 2026, reaching products already on the market 1. The rest applies from 11 December 2027 2.

    The gap is ownership, not knowledge. Roadmap, code and policy each have an owner; the manufacturer's duty has none. One loop closes it: governance decides the route and names the signatory, risk supplies the documented assessment and the component position, compliance leaves the file, the declaration and the reporting evidence.

    In scope: class, route, vulnerability handling, the support period, the file, a rehearsed reporting path.

    Out of scope: engineering the product, the assessment body's work, market surveillance.

    Phases

    PhasePurposePlanning horizonCloses when
    1. Scope and classWhich products, which annex category3–5 weeksEach product has a class decision
    2. RouteThe Article 32 procedure and the signatory4–8 weeksEach route is recorded with its reason
    3. Vulnerability handlingIntake, triage, update, disclosure — vulnerability handling and SBOM3–5 monthsOne record reaches disclosure
    4. Support period and componentsThe period, a position per outside component6–10 weeksEach product has a dated period
    5. DocumentationThe Annex VII file and the declaration — CRA technical documentation3–5 monthsA reader of the file signs it
    6. Article 14 rehearsalA timed run against the clocks2–4 weeksEach notification lands inside its clock
    Horizons are planning input, not elapsed time.

    Phase 2 is governance's decision, phase 4 risk's instrument, phase 5 what compliance shows an authority.

    Annex III core functionality makes a product important, Annex IV critical 3: obligations by product class. Class decides which Annex VIII procedures stay open 4: the conformity route. The period follows expected use, with a five-year floor unless that use is shorter 5: the support period decision. Components carry due diligence; a vulnerability in one goes to its maintainer 6: supply chain and components. Phase 6 tests 24 hours, 72 hours, then 14 days or one month 7: /radar#cra-reporting-obligations.

    Deliverables

    • Product inventory, class and route per product — everything else follows.
    • Class and route decision record, with the signatory — why each route was chosen.
    • Vulnerability handling record, one per issuevulnerability handling record.
    • Support-period statement and the component positions behind it — the reasoning, not the date.
    • Annex VII file index and the signed declarationCRA technical documentation index.
    • Reporting rehearsal record, timed against each clock — proof the path works.

    Roles

    RoleSideAccountable for
    ManufacturerOrganisationThe essential requirements, at the moment of placing 8
    Product security ownerOrganisationThe risk assessment, documented and kept current 9
    Compliance ownerOrganisationThe file and declaration, at authorities' disposal for ten years or the support period 10
    Incident ownerOrganisationThe reporting path and its rehearsal
    Product managementOrganisationThe support period and the class decision each product keys to
    AdviserExternalMethod, the class and route reasoning, rehearsal design

    What the authority asks

    Failure modes

    Frameworks

    InstrumentWhat it asksWhere it lands
    Regulation (EU) 2024/2847A documented assessment, current, available to authoritiesArticles 13(2), 13(3), 13(13)
    IEC 62443-4-1:2018Justified scoping, outside components, update timingSM-5, SM-9, SUM-5 11
    ISO/SAE 21434:2021Reviewed tailoring and assessment rationales, an incident response planClauses 6.4.3, 6.4.8, 13.3 12
    ISO/IEC 27001:2022Authorities, risk actions, operational control, auditClauses 5.3, 6.1, 8.1, 9.2 13
    What each instrument asks of the work.

    The boundary with the CSMS and the ISMS

    The product cybersecurity pattern builds a management system and its certificate. This work borrows ISMS machinery: authorities, operational control, an audit programme. The duty cannot be borrowed. Where both apply, governing security in the product organisation holds the decision rights.

    References

    1. European Parliament and Council. Regulation (EU) 2024/2847. OJ L, 2024/2847, 20.11.2024 14.
    2. IEC. IEC 62443-4-1:2018. https://webstore.iec.ch/en/publication/33615. Identifiers and titles, licensed copy, 2026-09-06.
    3. ISO and SAE International. ISO/SAE 21434:2021. https://www.iso.org/standard/70918.html. Clauses and titles, licensed copy, 2026-09-06.
    4. ISO/IEC. ISO/IEC 27001:2022. https://www.iso.org/standard/27001. Clause titles from the ISO Online Browsing Platform, 2026-09-03.

    Sources

    1. 1EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(3) · verified 2026-09-05
    2. 2EU Publications Office CELEX 32024R2847 Art. 71(2) and Art. 69(2) · verified 2026-09-05
    3. 3EU Publications Office CELEX 32024R2847 Art. 7(1), Art. 8(1), Annex III and Annex IV · verified 2026-09-05
    4. 4EU Publications Office CELEX 32024R2847 Art. 32(1) to 32(4) · verified 2026-09-05
    5. 5EU Publications Office CELEX 32024R2847 Art. 13(8) · verified 2026-09-05
    6. 6EU Publications Office CELEX 32024R2847 Art. 13(5) and Art. 13(6) · verified 2026-09-05
    7. 7EU Publications Office CELEX 32024R2847 Art. 14(2) and 14(4) · verified 2026-09-05
    8. 8EU Publications Office CELEX 32024R2847 Art. 13(1) and Annex I Part I · verified 2026-09-04
    9. 9EU Publications Office CELEX 32024R2847 Art. 13(2) and 13(3) · verified 2026-09-05
    10. 10EU Publications Office CELEX 32024R2847 Art. 13(13) · verified 2026-09-05
    11. 11IEC 62443-4-1:2018 SM-5, SM-9 and SUM-5, licensed copy · verified 2026-09-06
    12. 12ISO/SAE 21434:2021 clauses 6.4.3, 6.4.8 and 13.3, licensed copy · verified 2026-09-06
    13. 13ISO/IEC 27001:2022 clauses 5.3, 6.1, 8.1 and 9.2, iso.org/obp · verified 2026-09-03
    14. 14EU Publications Office CELEX 32024R2847, full text · verified 2026-09-05