ISMS & Risk

CRA Compliance

Products with digital elements: assessed for conformity, reported on time

The Cyber Resilience Act obliges manufacturers of products with digital elements to demonstrate security across the entire lifecycle. The CRA module ships the Annex I requirements as a control catalog, runs the conformity assessment in a structured way and produces the declaration of conformity. Actively exploited vulnerabilities and severe incidents run through a prepared reporting chain with the 24 and 72 hour deadlines. You do not reinvent the evidence: it is mapped to vulnerability management, the risk register, supplier management and the other modules you maintain anyway.

CRA (EU) 2024/2847
Features

Your benefits

1

Annex I as a control catalog

The essential CRA requirements come as a structured catalog. You assess control by control instead of translating the regulation text into spreadsheets yourself.

2

Reporting chain for 24 and 72 hours

Early warning after 24 hours, follow-up after 72, final report thereafter: deadlines are computed from the moment of becoming aware, and each stage carries its own status. The module produces the content; transmission to the single platform currently happens by export, because that interface is still being built.

3

Declaration of conformity at the press of a button

The completed assessment produces the declaration of conformity (DoC) as a document, versioned and traceable.

4

Evidence from existing modules

CRA controls reference what is already there: vulnerability management, the risk register, supplier management, attack surface management. One piece of evidence, used many times.

Capabilities

Capabilities in detail

  • Product profile for each product with digital elements
  • Product class and conformity route as the basis of the assessment
  • Date of placing on the market, decisive for the transitional rules
  • Support period for security updates per product
  • Intended use and scope of the essential requirements
  • Annex I as a control catalog, assessable control by control
  • Product profile linked to the OSCAL system security plan
  • Declaration of conformity with number, version and status
  • Standards applied and notified body recorded in the declaration
  • Snapshot of manufacturer and plan data at the time of issue
  • Withdrawing a declaration as a state of its own
  • Technical documentation ordered by annex section
  • Evidence as a reference to existing objects instead of a copy
  • Flagging an incident as CRA-reportable, with its own reference number
  • Moment of becoming aware as the anchor for every deadline
  • Separation by report type and reporting recipient
  • Three reporting stages, each with its own timestamp and status
  • Stage-specific report content for export and manual submission
  • Cockpit for conformity status and open reporting deadlines
Result

CRA compliance as a guided process instead of regulation reading: assessed against Annex I, ready to report within 24 hours, evidenced from day-to-day operations.

Experience CRA Compliance live

Schedule a no-obligation demo – we will show you the module with your own use cases.