5 Compiling for Compliance: CRA Mandated Technical Documentation

What Role Does Technical Documentation Play in CRA Compliance?

Compliance is proven through documentation and under Chapter III of the CRA. Technical documentation is an integral part defining the conformity of a product with digital elements. Additionally, the CRA sets forth requirements for the documentation to be continuously updated and maintained throughout the product’s support period.
Table 5-1. Summary of Conformity Assessment Routes
Product CategorySelf-Assessment Allowed?Notified Body Required?Details
Default (most products)Yes (Module A)NoManufacturer does everything internally, issues the Declaration of Conformity, and applies the CE mark.
Important – Class IYes, but with conditionsSometimesAllowed through self-assessment only if you fully apply harmonized standards or common specifications. Otherwise, a Notified Body is required.
Important – Class IINoYesMandatory third-party assessment by a Notified Body.
CriticalNoYesMandatory Notified Body (or European cybersecurity certification scheme).

What Information Should be Documented to Comply with the CRA?

Annex VII of the CRA is dedicated to the information that should be prepared by manufacturers when they want to declare conformity to the CRA guidelines. Not all of this information must be made available to the public, but having it on hand is good practice in case of market inspection.

Declaration of Conformity

A declaration of conformity (DoC) is a mandatory legal document that an authorized representative of a manufacturer must sign to declare that their products comply with all EU requirements. It is a document that carries a lot of legal weight as it affirms that the manufacturers have undertaken all the necessary assessments and compiled all the documentation to prove compliance.

SBOM

In the case of software products or a combination of hardware and software products, an SBOM is required as a transparency measure, ensuring that these products and their components are carefully vetted and assessed for vulnerabilities.

General Product Description

Manufacturers shall provide a description of the product, including its intended and foreseeable purpose, compliant versions, photos or illustration of the product’s external features and internal layout, and instructions for the users.

Product System Architecture

Drawings and schematics of the system architecture explain how hardware and software components build on or feed into each other and integrate into the overall processing.

Vulnerability Handling Process

Manufacturers must provide information on the vulnerability handling processes put in place to mitigate risks and address reported threats. Implementing a coordinated vulnerability disclosure policy, providing contact details for reporting incidents and vulnerabilities, and establishing mechanisms for the secure distribution of updates fulfill this requirement.

Threat Analysis and Risk Assessment

An assessment of the cybersecurity risks affecting the product, and the essential cybersecurity requirements applicable to the product, must be maintained and documented by the manufacturer.

Support Period Rationale

Relevant information detailing and justifying the support period set by the manufacturer, during which vulnerabilities will be handled effectively, should be documented and maintained.

Applied Standards

In the case where a product also complies with other standards (i.e., ISO21434, IEC62443, EN303-645), common specifications, or cybersecurity schemes, this must also be disclosed and documented.

Test Conformity Reports

Reports of tests carried out to verify that the product conforms to the CRA requirements must be filed and kept for posterity to affirm that due diligence has been done in ensuring that the product is secure.

Should all the CRA Documentation be Made Available to the Public?

No. Some of the documentation is meant to be kept internally until the manufacturer is required to produce it as evidence of compliance. The following table shows a handy guide to which documents should be kept internally and which should be made available to customers.

Table 5-2. Documentation Guide
Documents to Keep InternallyDocuments to Give to Customers
Copy of the EU Declaration of ConformityEU Declaration of Conformity
Product System ArchitectureGeneral Product Description
Threat Assessment and Risk Analysis, Vulnerability Report Vulnerability Handling Process, Procedures, and Policies
SBOMSBOM (optional or as stipulated in the contract)
Test Reports
Vulnerability Handling Process, Procedures, and Policies
Applied Standards
Support Period Rationale

Action Checklist

  • Review the list of collateral, documentation, and guides being released for each product.
  • Identify which documents are missing based on the requirements and determine which existing documents can be improved or modified to satisfy the requirements.
  • Create a central repository for "Proof of Compliance" for each product and each version of a product.
  • Develop processes that ensure CRA-required documentation is included as part of the final package of a product.
  • In case of any informal or verbal-only policies regarding security, formalize them as policy and document them.