CRA compliance checklist for manufacturers

If you place products with digital elements on the EU market, the Cyber Resilience Act, Regulation (EU) 2024/2847, makes you responsible for security by design, vulnerability handling, technical documentation and conformity marking. This checklist walks through the core obligations manufacturers should be able to evidence before the main obligations apply on 11 December 2027, with reporting readiness needed earlier, from 11 September 2026.

The core checklist

Documentation and retention

Two documents anchor your conformity story: the Annex VII technical documentation and the EU declaration of conformity. Both must be retained for at least 10 years after the product is placed on the market, or for the support period if that is longer (Article 13(13)). Treat this as a long-lived records obligation, not a one-off at launch, because the documentation must reflect the product as it evolves.

Keep the SBOM synchronised with each release. When a component changes, the record of top-level dependencies should change with it, so that your technical documentation stays an accurate account of what you shipped.

Conformity assessment route

The route you follow depends on the product. Most products follow the default route, but "important" and "critical" products in Annexes III and IV trigger stricter conformity assessment routes. Commission Implementing Regulation (EU) 2025/2392 of 28 November 2025 sets out the technical descriptions of those categories, so check it if your product might qualify. The conformity assessment bodies that carry out third-party assessment are governed by Chapter IV (Articles 35 to 51), which applies from 11 June 2026.

How CRANIS2 helps

CRANIS2 turns this checklist into a living record: it tracks your SBOM and top-level dependencies, keeps vulnerability handling and reporting readiness in one place, and holds your technical documentation and declaration of conformity against the 10-year retention requirement. It also flags where a product may fall into an important or critical class. Begin with a structured conformity assessment.

Frequently asked questions

Does the SBOM have to be published?

No. Annex I Part II requires you to identify and document components, including an SBOM in a commonly used machine-readable format covering at least the top-level dependencies, but it sits within the Annex VII technical documentation and is not required to be public.

How long must I keep the technical documentation?

At least 10 years after the product is placed on the market, or for the support period if that is longer, under Article 13(13).

Can I charge for security updates?

No. Security updates must be free of charge through the support period, which is at least 5 years unless a shorter expected product lifetime justifies less (Article 13(8)).


Related guides: Does the CRA apply to my product? and CRA reporting obligations from September 2026.