5 Compiling for Compliance: CRA Mandated Technical Documentation
What Role Does Technical Documentation Play in CRA Compliance?
| Product Category | Self-Assessment Allowed? | Notified Body Required? | Details |
|---|---|---|---|
| Default (most products) | Yes (Module A) | No | Manufacturer does everything internally, issues the Declaration of Conformity, and applies the CE mark. |
| Important – Class I | Yes, but with conditions | Sometimes | Allowed through self-assessment only if you fully apply harmonized standards or common specifications. Otherwise, a Notified Body is required. |
| Important – Class II | No | Yes | Mandatory third-party assessment by a Notified Body. |
| Critical | No | Yes | Mandatory Notified Body (or European cybersecurity certification scheme). |
What Information Should be Documented to Comply with the CRA?
Annex VII of the CRA is dedicated to the information that should be prepared by manufacturers when they want to declare conformity to the CRA guidelines. Not all of this information must be made available to the public, but having it on hand is good practice in case of market inspection.
Declaration of Conformity
A declaration of conformity (DoC) is a mandatory legal document that an authorized representative of a manufacturer must sign to declare that their products comply with all EU requirements. It is a document that carries a lot of legal weight as it affirms that the manufacturers have undertaken all the necessary assessments and compiled all the documentation to prove compliance.
SBOM
In the case of software products or a combination of hardware and software products, an SBOM is required as a transparency measure, ensuring that these products and their components are carefully vetted and assessed for vulnerabilities.
General Product Description
Manufacturers shall provide a description of the product, including its intended and foreseeable purpose, compliant versions, photos or illustration of the product’s external features and internal layout, and instructions for the users.
Product System Architecture
Drawings and schematics of the system architecture explain how hardware and software components build on or feed into each other and integrate into the overall processing.
Vulnerability Handling Process
Manufacturers must provide information on the vulnerability handling processes put in place to mitigate risks and address reported threats. Implementing a coordinated vulnerability disclosure policy, providing contact details for reporting incidents and vulnerabilities, and establishing mechanisms for the secure distribution of updates fulfill this requirement.
Threat Analysis and Risk Assessment
An assessment of the cybersecurity risks affecting the product, and the essential cybersecurity requirements applicable to the product, must be maintained and documented by the manufacturer.
Support Period Rationale
Relevant information detailing and justifying the support period set by the manufacturer, during which vulnerabilities will be handled effectively, should be documented and maintained.
Applied Standards
In the case where a product also complies with other standards (i.e., ISO21434, IEC62443, EN303-645), common specifications, or cybersecurity schemes, this must also be disclosed and documented.
Test Conformity Reports
Reports of tests carried out to verify that the product conforms to the CRA requirements must be filed and kept for posterity to affirm that due diligence has been done in ensuring that the product is secure.
Should all the CRA Documentation be Made Available to the Public?
No. Some of the documentation is meant to be kept internally until the manufacturer is required to produce it as evidence of compliance. The following table shows a handy guide to which documents should be kept internally and which should be made available to customers.
| Documents to Keep Internally | Documents to Give to Customers |
|---|---|
| Copy of the EU Declaration of Conformity | EU Declaration of Conformity |
| Product System Architecture | General Product Description |
| Threat Assessment and Risk Analysis, Vulnerability Report | Vulnerability Handling Process, Procedures, and Policies |
| SBOM | SBOM (optional or as stipulated in the contract) |
| Test Reports | – |
| Vulnerability Handling Process, Procedures, and Policies | – |
| Applied Standards | – |
| Support Period Rationale | – |
Action Checklist
- Review the list of collateral, documentation, and guides being released for each product.
- Identify which documents are missing based on the requirements and determine which existing documents can be improved or modified to satisfy the requirements.
- Create a central repository for "Proof of Compliance" for each product and each version of a product.
- Develop processes that ensure CRA-required documentation is included as part of the final package of a product.
- In case of any informal or verbal-only policies regarding security, formalize them as policy and document them.
