
CRA checklist
Cyber Resilience Act checklist: what manufacturers have to do
Nine steps from the product list to CE marking, each with the article or annex of Regulation (EU) 2024/2847, the tasks to tick off and the result that should be in place at the end.
The three key dates for manufacturers
10 Dec 2024
Regulation enters into force
11 Sep 2026
Article 14 reporting obligations apply, including to products placed on the market before 11 Dec 2027
11 Dec 2027
The remaining manufacturer obligations apply, including Annex I, technical documentation and CE marking
The checklist
The order follows the dependencies: no product class without a product list, no reliable Annex I implementation without a risk assessment. Step 7 already applies and therefore comes first. The checklist summarises the main manufacturer obligations and is not exhaustive; the text of Regulation (EU) 2024/2847 is authoritative.
- Step 1Art. 2, Art. 3, Art. 69
Record your products and assess the scope
The CRA applies to products with digital elements whose intended purpose or reasonably foreseeable use includes a direct or indirect logical or physical data connection to a device or network. This covers hardware and software including their remote data processing solutions, and components placed on the market separately. Some products are excluded because other legislation applies, such as medical devices and in vitro diagnostic medical devices, type-approved motor vehicles and aviation products certified under Regulation (EU) 2018/1139.
Result: A product register with a technical assessment per product and the facts it is based on.
- Step 2Art. 13, 19, 20, 21, 22
Establish the role per product
Obligations depend on the role. Manufacturers carry most of them, importers and distributors have their own verification duties. Anyone who places a product on the market under their own name or substantially modifies it may become a manufacturer.
Result: Role per product as a working basis, open cases flagged for review by your legal department.
- Step 3Art. 7, 8, 32, Annex III and IV
Determine product class and conformity assessment route
Without an entry in Annex III or IV, internal control (module A) is sufficient. For important products in class I this applies only if harmonised standards, common specifications or a European cybersecurity certification scheme at assurance level at least ‘substantial’ are applied in full; otherwise a notified body is needed (modules B and C or module H). Class II always requires one of these procedures or a certification scheme at assurance level at least ‘substantial’. For critical products under Annex IV, European certification applies where required under Article 8(1), otherwise the same procedures as for class II.
Result: Product class and intended conformity assessment route per product.
- Step 4Art. 13(2) to (4)
Cybersecurity risk assessment per product
The risk assessment is the basis for everything else: it determines which Annex I requirements are implemented and how. It is documented, included in the technical documentation and kept up to date during the support period.
Result: A documented risk assessment per product, ready for the technical documentation.
- Step 5Annex I Part I
Implement the security requirements of Annex I Part I
Based on the risk assessment, products must, where applicable, among other things be made available without known exploitable vulnerabilities and with a secure default configuration, allow security updates, protect against unauthorised access, protect the confidentiality and integrity of data, limit the attack surface, log security-relevant events and allow all data to be deleted securely.
Result: Implementation status per requirement with evidence, open points in the action plan.
- Step 6Annex I Part II, Art. 13(5) and (6)
SBOM and vulnerability handling under Annex I Part II
Manufacturers must identify and document components and vulnerabilities, including by drawing up a software bill of materials in a commonly used machine-readable format covering at least the top-level dependencies. Vulnerabilities must be remediated without delay, and fixed vulnerabilities disclosed once the update is available. Due diligence applies to third-party components.
Result: An SBOM per release, a working vulnerability process and a published CVD policy.
- Step 7Art. 14, Art. 16, Art. 69(3)Already applies
Operate the Article 14 reporting process
Actively exploited vulnerabilities and severe incidents having an impact on the security of the product must be notified through the single reporting platform simultaneously to the CSIRT designated as coordinator and to ENISA: an early warning notification without undue delay and in any event within 24 hours of becoming aware, a notification without undue delay and in any event within 72 hours. The final report follows, for a vulnerability, no later than 14 days after a corrective or mitigating measure is available, and for an incident within one month of the notification.
Result: A reporting process that can meet the deadlines, with named roles and templates.
- Step 8Art. 13(8), (9) and (19), Annex II(7)
Define the support period
The support period during which vulnerabilities are handled reflects the time the product is expected to be in use and is at least five years. Where the product is expected to be in use for less than five years, it corresponds to the expected use time. Security updates made available remain available for at least ten years or for the remainder of the support period, whichever is longer.
Result: A defined support period with end date per product.
- Step 9Art. 13(13) and (15) to (17), Art. 28, 30, 31, 32, Annex II and VII
Technical documentation, user information and CE marking
Before placing a product on the market from 11 December 2027, the technical documentation under Annex VII, the information and instructions to the user under Annex II, the conformity assessment, the EU declaration of conformity and CE marking must be in place. Documentation and declaration are kept for at least ten years or for the support period, whichever is longer.
Result: Documentation per product, ready for the conformity assessment and market surveillance.
Frequently asked questions
Where should manufacturers start now?+
With the Article 14 reporting process, because it has applied since 11 September 2026, and in parallel with the product list. Without a product list neither the class can be determined nor the remaining effort planned.
Does the CRA apply to products already on the market?+
The Article 14 reporting obligations also apply to products placed on the market before 11 December 2027 (Art. 69(3)). The other requirements apply to such products only if they are substantially modified after that date (Art. 69(2)). What counts is the individual unit: if a model is still placed on the market after 11 December 2027, every unit placed on the market from then on must meet the requirements (recital 38).
Which format does the SBOM need?+
The CRA requires a commonly used machine-readable format covering at least the top-level dependencies. The Regulation does not name a specific format; the Commission may specify format and elements by implementing acts (Art. 13(24)). CycloneDX and SPDX are widely used.
Do I need a notified body?+
That depends on the product class. For products not listed in Annex III or IV, internal control is sufficient. For class I only if harmonised standards, common specifications or a certification scheme at assurance level at least ‘substantial’ are applied in full. For class II and critical products, third-party assessment is required.
Does this checklist replace a case-by-case assessment?+
No. It describes the obligations in general. Whether and how they apply to a specific product depends on the individual case; legal questions are settled by your legal department or counsel.
This content provides general technical and organizational information on the Cyber Resilience Act (Regulation (EU) 2024/2847) and does not constitute legal advice (no legal services within the meaning of the German RDG).
Last updated: 2026-10-08
Kontakt aufnehmen
Apply the checklist to your products
In the CRA gap analysis we work through these steps with your teams from a technical perspective, give a technical assessment of role and product class per product, flag legal questions for your legal department and deliver a gap report and action plan. The initial call is free and without obligation.