CVD Portal · Conformity workspace

The CRA conformity workspace, from classification to CE marking.

Classify each product under Annex III and IV, run the risk assessment, close the Annex I gaps, and draft your technical file and EU Declaration of Conformity. Vulnerability handling and Article 14 authority reporting run in the same workspace. Fines for breaching the essential obligations reach €15 million or 2.5% of worldwide turnover.

New accounts include 14 days of the Compliance plan. The disclosure portal stays free.

Or run the free CRA exposure scan on your domain
What happens if you ignore it

The price of doing nothing is written into the law.

Fines

Up to €15 million or 2.5% of worldwide turnover

Breaching the essential cybersecurity obligations carries administrative fines of up to €15 million or 2.5% of total worldwide annual turnover, whichever is higher (Art. 64(2)).

Market access

Products can be restricted or pulled from the EU market

Market surveillance authorities can require corrective action, restrict availability, or prohibit a non-compliant product on the EU market.

Buyer pressure

Enterprise buyers ask for CRA conformity evidence

Procurement and security teams increasingly ask for a documented CRA position, a chosen conformity assessment route, and a published disclosure process before they sign.

The Compliance plan takes you through the self-assessment. Report intake and acknowledgment stay free. Here is what each plan covers.

How it works

From first login to a documented CRA position.

See the full walkthrough →
01

Classify your products

Add a product and answer the Annex III and IV classification questions. The engine determines the product class and your Article 32 conformity assessment route.

02

Assess and close the gaps

Run the STRIDE risk assessment, work through the 22 Annex I essential requirements, and follow the gap analysis to remediation guidance for every open item.

03

Produce the evidence

Draft the technical documentation and EU Declaration of Conformity, then publish your disclosure portal so vulnerability reports and Article 14 notifications run through one system.

The compliance workspace

One workspace per product, from classification to conformity.

Every product gets its own workspace. The classification drives the Article 32 route, the risk assessment feeds the Annex I checklist, and gap analysis shows exactly what is open. Evidence accumulates per requirement, and the technical documentation and EU Declaration of Conformity are drafted from the recorded state instead of written from scratch. Where the classification puts a product on a third-party route, that same recorded state is the file the notified body assesses.

Annex I requirementsSample data
CVD Portal product workspace showing the Annex I requirements checklist with classification, conformity route, and progress tracking
See the product

The whole compliance workspace, live and clickable.

Open a read-only demo of Aurelia Devices B.V., a fictional manufacturer running the full platform. Walk the compliance dashboard, a worked product risk assessment, the generated conformity documents, and the vulnerability disclosure register, all with real sample data. Open it instantly, no signup.

Vulnerability registerAurelia Devices B.V., a fictional manufacturer
CVD Portal dashboard showing the vulnerability register with CRA compliance status
THE FIVE CRA OBLIGATION AREAS

Everything the Cyber Resilience Act asks of a manufacturer

One workspace covering all five CRA obligation areas, from product classification and risk assessment through documentation, vulnerability handling, and authority reporting.

Disclosure intake and acknowledgment are free. The self-assessment suite is on the Compliance plan, covering Module A for default-class products and the technical file for products that need a notified body.

Classification

Product Classification and Conformity Route

Answer the Annex III and IV questions for each product. The engine determines whether the product is default, important, or critical and which Article 32 conformity assessment route applies.

Annex III / IV classificationCompliance
Article 32 conformity routeCompliance
Assessment snapshots as point of recordCompliance
Risk Assessment

STRIDE Risk Assessment

A structured threat model per product with likelihood and impact scoring across 33 security objectives, feeding directly into the Annex I requirements work.

STRIDE threats with L×I scoringCompliance
33 security objectivesCompliance
Monitoring and review triggersCompliance
Annex I

Essential Requirements and Gap Analysis

Work through the 22-row Annex I essential requirements checklist. Gap analysis shows what is open and remediation guidance shows how to close it.

22-row Annex I checklistCompliance
Gap analysis and remediation guidanceCompliance
Assignment and delegation via magic linksCompliance
Documentation

Technical File and Declaration of Conformity

Draft artifacts clause by clause with AI assistance across 88 CRA clause artifacts, then generate the EU Declaration of Conformity, the Annex VII documentation index, and the Annex II user information sheet, with CE marking guidance.

AI drafting over 88 clause artifactsCompliance
EU Declaration of Conformity (Annex V)Compliance
Evidence management with AI control mappingCompliance
Vulnerability Handling

Disclosure Portal and Article 14 Reporting

A branded intake portal on your own subdomain with structured submissions, PGP, security.txt, and a full audit trail. Article 14 milestones to ENISA/CSIRT run on fixed deadlines with SRP-ready packages.

Branded portal, intake, 48h acknowledgmentFree
24h / 72h / final Article 14 filingsReporting
CSAF 2.0 export and SBOM managementReporting
Supply Chain and Scale

Partners, Trust Portal, and Integrations

Assess supply chain partners with CVD scanning, VEX, and SBOM matching. Share conformity documents with approved external viewers through a trust portal, with API access and SAML SSO.

Partner assessment (CVD scan, VEX, SBOM)Compliance
Trust portal for external viewersEnterprise
API access and SAML SSOEnterprise
COMPLIANCE CHECKLIST

Are You CRA Ready?

Loading...

EU buyers and market surveillance authorities increasingly expect manufacturers to show a documented CRA position. CVD Portal gives you a structured assessment, the technical file to back it, and a published disclosure process.

ISO 29147EN 40000-1-3CSAF 2.0EU HostedGDPR Compliant
EU Cyber Resilience Act Timeline
Read the full timeline →
November 2024

CRA Published

Regulation (EU) 2024/2847 enters into force

September 2026

Article 14 Reporting Begins

Vulnerability notification obligations apply to products in scope

December 2027

Full Conformity Deadline

Annex I essential requirements, technical documentation, and CE marking apply

Start your CRA self-assessment before the deadlines arrive

Article 14 reporting obligations apply from 11 September 2026 and full conformity, including Annex I and CE marking, applies from 11 December 2027. Every new account starts with 14 days of the Compliance plan. New to the regulation? Read the EU Cyber Resilience Act regulation guide first.

Or set up the free disclosure portal first